Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

241–250 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#241
post #143

Earlier quoted context omitted.

I registered it about 40 minutes ago, but it seems the DNS has been cached by everyone as a result of the wikipedia hack & not even the NS is propagating. Can't get an SSL certificate .

I had looked into its availability too just out of curiosity itself before reading your comment on a provider, Then I read your comment. Atleast its taken in from the hackernews community and not a malicious actor. Do keep us updated on the whole situation if any relevant situation can happen from your POV perhaps. I'd suggest to give the domain to wikipedia team as they might know what could be the best use case of…

This community has no malicious actors? :)

Re: Wikipedia was in read-only mode following mass admin account compromise

#242
post #36

Wow. This worm is fascinating. It seems to do the following: - Inject itself into the MediaWiki:Common.js page to persist globally, and into the User:Common.js page to do the same as a fallback - Uses jQuery to hide UI elements that would reveal the infection - Vandalizes 20 random articles with a 5000px wide image and another XSS script from basemetrika.ru - If an admin is infected, it will use the Special:Nuke page…

Wouldn't be surprised if elaborate worms like this are AI-designed

I mean....elaborate is a stretch.

Re: Wikipedia was in read-only mode following mass admin account compromise

#243
post #125

See the public phab ticket: https://phabricator.wikimedia.org/T419143 In short, a Wikimedia Foundation account was doing some sort of test which involved loading a large number of user scripts. They decided to just start loading random user scripts, instead of creating some just for this test. The user who ran this test is a Staff Security Engineer at WMF, and naturally they decided to do this test under their highly…

This is a pretty egregious failure for a staff security engineer

Re: Wikipedia was in read-only mode following mass admin account compromise

#244

Earlier quoted context omitted.

True but it does say something that such a script was able to lie dormant for so long.

Why would anyone test in production???!!!

Selecting the wrong environment in your test setup by mistake?

I refuse to believe that someone on the security team intentionally tested random user scripts in production on purpose.

Re: Wikipedia was in read-only mode following mass admin account compromise

#245
post #125

See the public phab ticket: https://phabricator.wikimedia.org/T419143 In short, a Wikimedia Foundation account was doing some sort of test which involved loading a large number of user scripts. They decided to just start loading random user scripts, instead of creating some just for this test. The user who ran this test is a Staff Security Engineer at WMF, and naturally they decided to do this test under their highly…

On one hand, I was about to get irrationally angry someone was attacking Wikipedia, so I'm a bit relieved

On the other hand,

>a Staff Security Engineer at WMF, and naturally they decided to do this test under their highly-privileged Wikimedia Foundation staff account

seriously?

Re: Wikipedia was in read-only mode following mass admin account compromise

#246
post #221

Earlier quoted context omitted.

Kudos for very polite responses to trolling.

no one is trolling in this comment chain. i found kibone's reply to a hypothetical musing as if it was some counterpoint in a debate instead of a simple expansion on their comment to be off putting. we had some comments back and forth and we both came out of it just fine. weird of you to add on this little insult to an otherwise pretty normal exchange.

FWIW I did not assume that you were trolling, and yes we did come out fine.

Re: Wikipedia was in read-only mode following mass admin account compromise

#247

Earlier quoted context omitted.

That's not a lot of state lost. Destructive operations are easier to replay than constructive ones.

Is Wikimedia overreacting then?

No: from what I can tell, they're being conservative, which is appropriate here. Once you've pushed the "stop bad things happening" button, there's no need to rush.

Re: Wikipedia was in read-only mode following mass admin account compromise

#248

This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…

For reference

>There are currently 15 interface administrators (including two bots).

https://en.wikipedia.org/wiki/Wikipedia:Interface_administra...

Re: Wikipedia was in read-only mode following mass admin account compromise

#249
post #237

Earlier quoted context omitted.

Didn't realise this was some historic evil script and not some active attacker who could change tack at any moment. That makes the fix pretty easy. Write a regex to detect the evil script, and revert every page to a historic version without the script.

Letting ancient evil code run? Have we learned nothing from A Fire Upon the Deep ?!

I've only just heard of it. But, I already knew to not run random scripts under a privileged account. And thank you for the book suggestion - I'm into those kinds of tales.

Re: Wikipedia was in read-only mode following mass admin account compromise

#250
post #125

See the public phab ticket: https://phabricator.wikimedia.org/T419143 In short, a Wikimedia Foundation account was doing some sort of test which involved loading a large number of user scripts. They decided to just start loading random user scripts, instead of creating some just for this test. The user who ran this test is a Staff Security Engineer at WMF, and naturally they decided to do this test under their highly…

This is a pretty egregious failure for a staff security engineer

Pretty much the definition of a “career limiting event”
Post reply on HN