Live data from Hacker News

Skype blog hacked

blogs.skype.com

31–40 of 61 posts

Re: Skype blog hacked

#31
post #8
post #6

Earlier quoted context omitted.

You're right. It was probably a brute force since they don't have maximum login attempts. http://blogs.skype.com/wp-admin

Such a simple feature to implement...

It does appear to be a brute force or phishing attack. These sort of drive-bys can typically be permanently stopped with 2FA or a password-less MFA solution like LaunchKey (Disclaimer: co-founder). LaunchKey has a free WordPress Plugin available, among others: http://wordpress.org/plugins/launchkey/

It is 2014, you better prepare a good PR response for when you get breached OR start implementing stronger authentication ASAP.

Re: Skype blog hacked

#32
post #24
post #22

Earlier quoted context omitted.

You will find those usernames whenever you scan wordpress.com with wpscan.

Wow you are right about that. just did it on another blog.wordpress.com. How come? On Skype's blog I can access /author/7 or /author/ian but I can't do it on another blog, I get "Oops".

I think they are trying ?author=1, ?author=2, etc

Re: Skype blog hacked

#33
post #19

I'm not sure why the accent on "Stop using MS, it's spying on you!" is on MS. AFAIK every company is using your data and giving/selling it to the government. How is MS more evil than anyone else?

If someone drowns 4 kittens and you only drown 1 kitten, you're still pretty evil. I don't see how "everyone else is doing it" is possibly a valid argument. Obviously 'evil' in this case is based on your definition though, it's not exactly a universal concept.

What if a cop held a gun to your head and told you to drown those kittens?

Re: Skype blog hacked

#34
>> Hacked by Syrian Electronic Army.. Stop spying!

Seems a strange message to send to a country that spies on it's own citizens (and where apparently the citizens are unable to prevent their own government from doing it to them).

Re: Skype blog hacked

#36
post #23

Earlier quoted context omitted.

Looks to be one of those auto posters (i.e. content posted on the blog is automatically pushed out to twitter, facebook, others)

I thought so as well, until https://twitter.com/Skype/statuses/4184954534710681

Ahh, I see. Interesting!

Re: Skype blog hacked

#37
post #25
post #10

I don't consider getting access to a website via the most insecure blogging platform on the internet "hacking".

Not sure why you say that. WordPress.com offers 2-Factor Auth: http://en.support.wordpress.com/security/two-step-authentica... There are also tons of available security plugins & pretty extensive documentation on hardening a self-hosted install: http://wordpress.org/plugins/tags/security http://codex.wordpress.org/Hardening_WordPress

Still, a lot of what's on that page and a lot of the common features of plugins like Wordfence (which I use) should be part of the core, I think.

Though also in my opinion even having a web-based file editor is pretty terrible...

Re: Skype blog hacked

#39
post #34

>> Hacked by Syrian Electronic Army.. Stop spying! Seems a strange message to send to a country that spies on it's own citizens (and where apparently the citizens are unable to prevent their own government from doing it to them).

Indeed and they buy german spying technology products. However I think the logical fallacy you've stepped in is that the Syrian Electronic Army (SEA) doesn't want to get spied on themselves by Skype and Microsoft, maybe. haha :)

But I fully support the message here, I think that spying inside of consumer products is a sign of the abuse of power and monopoly.

Re: Skype blog hacked

#40
post #6
post #4

This blog is not hosted by the Skype but on WordPress VIP. This means that, most likely, the blog was not broken into using a software exploit of any sort since the security on VIP blogs is professional. Knowing that this is the Syrian Army, this attack was most likely done using phished credentials. If they had any sort of system access they would have defaced the entire subdomain or the main site. So most likely, t…

You're right. It was probably a brute force since they don't have maximum login attempts. http://blogs.skype.com/wp-admin

Limiting login attempts is not as effective as you might think. How should it work? If you want to ban IP addresses that get X attempts wrong in Y minutes, then you're failing to realize that hackers like this normally have access to hundreds or thousands of IP addresses. If you want to lock the whole account for a while, then you've just introduced a way for anyone to lock the account of someone else they don't like.

Also considering that their Twitter and Facebook accounts were also compromised, your assumption that it was the blog itself that was compromised is a big one. I don't have any first hand knowledge on that though personally, I'm just saying.

Post reply on HN