Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

71–80 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#71

Wow. This worm is fascinating. It seems to do the following: - Inject itself into the MediaWiki:Common.js page to persist globally, and into the User:Common.js page to do the same as a fallback - Uses jQuery to hide UI elements that would reveal the infection - Vandalizes 20 random articles with a 5000px wide image and another XSS script from basemetrika.ru - If an admin is infected, it will use the Special:Nuke page…

> Vandalizes 20 random articles with a 5000px wide image and another XSS script from basemetrika.ru

Note while this looks like its trying to trigger an xss, what its doing is ineffective, so basemetrika.ru would never get loaded (even ignoring that the domain doesnt exist)

Re: Wikipedia was in read-only mode following mass admin account compromise

#72

I completely understand marking the software that controls drinking water as critical infrastructure- but at some point a state based cyber attack that just wipes wikipedia off the net is deeply damaging to our modern society’s ability to agree on common facts … Just now thought “if Wikipedia vanished what would it mean … and it’s not on the level of safe drinking water, but it is a level.

All persistent data should have backup.

It's not a high bar.

Re: Wikipedia was in read-only mode following mass admin account compromise

#73
post #13

Earlier quoted context omitted.

PHP is the language where "return flase" causes it to return true. https://danielc7.medium.com/remote-code-execution-gaining-do...

Also the language that runs half of the web. Also the language that has made me millions over my career with no degree. Also the language that allows people to be up and running in seconds (with or without AI). I could go on.

Perl still runs the other half?

Re: Wikipedia was in read-only mode following mass admin account compromise

#74

I completely understand marking the software that controls drinking water as critical infrastructure- but at some point a state based cyber attack that just wipes wikipedia off the net is deeply damaging to our modern society’s ability to agree on common facts … Just now thought “if Wikipedia vanished what would it mean … and it’s not on the level of safe drinking water, but it is a level.

There are so many mirrors anyway and trivial to get a local copy? What is much more concerning is government censorship and age verification/digital id laws where what articles you read becomes part of your government record the police sees when they pull you over.

Re: Wikipedia was in read-only mode following mass admin account compromise

#75
post #57
post #47

Earlier quoted context omitted.

Ok, so there are tons of mediawiki installations all over the internet. What do these operators do? Set their wikis to read-only mode, hang tight, and wait for a security patch? Also, does this worm have a name?

There is nothing to do, the incident was not caused by a vulnerability in mediawiki. Basically someone who had permissions to alter site js, accidentally added malicious js. The main solution is to be very careful about giving user accounts permission to edit js. [There are of course other hardening things that maybe should be done based on lessons learned]

Well, admins (or anybody other than the developers / deployment pipeline) having permissions to alter the JS sounds like a significant vulnerability. Maybe it wasn't in the early 2000s, but unencrypted HTTP was also normal then.

Re: Wikipedia was in read-only mode following mass admin account compromise

#76
post #22

Earlier quoted context omitted.

As someone on the Wikipediocracy forums pointed out, basemetrika.ru does not exist. I get an NXDomain response trying to resolve it. The plot thickens.

Yeah, basemetrika.ru is free now. Should we occupy it? ;)

Namecheap won’t sell it which is great because it made me pause and wonder whether it's legal for an American to send Russians money for a TLD.

Re: Wikipedia was in read-only mode following mass admin account compromise

#77
post #36

Wow. This worm is fascinating. It seems to do the following: - Inject itself into the MediaWiki:Common.js page to persist globally, and into the User:Common.js page to do the same as a fallback - Uses jQuery to hide UI elements that would reveal the infection - Vandalizes 20 random articles with a 5000px wide image and another XSS script from basemetrika.ru - If an admin is infected, it will use the Special:Nuke page…

Wouldn't be surprised if elaborate worms like this are AI-designed

I would. AI designed software in general does not include novel ideas. And this is the kind of novel software AI is not great at, because there's not much training data.

Of course it's very possible someone wrote it with AI help. But almost no chance it was designed by AI.

Re: Wikipedia was in read-only mode following mass admin account compromise

#79
post #22

Earlier quoted context omitted.

As someone on the Wikipediocracy forums pointed out, basemetrika.ru does not exist. I get an NXDomain response trying to resolve it. The plot thickens.

Yeah, basemetrika.ru is free now. Should we occupy it? ;)

It means giving money to the Russian government, so no.

If anyone from the Russian government is reading this, get the fuck out of Ukraine. Thank you.

Re: Wikipedia was in read-only mode following mass admin account compromise

#80
post #28

How do they know? Has this been published in a Reliable Source?

This is the official Wikimedia Foundation status page for the whole of Wikipedia, so it's a reliable primary source.

Actually, usage of primary sources is kinda complicated [0], generally Wikipedia prefers secondary and tertiary sources.

[0] https://en.wikipedia.org/wiki/Wikipedia:No_original_research...

Post reply on HN