5 ms·
If anyone is interested in the other places their links were placed, you can see SEOMoz's backlink data - http://www.opensiteexplorer.org/links?site=seonix.org
by InfinityX0 15y ago
If anyone is interested in the other places their links were placed, you can see SEOMoz's backlink data - http://www.opensiteexplorer.org/links?site=seonix.org http://www.opensiteexplorer.org/links?site=seonix.org.
- danso 15y agoI would've liked to see an exact explanation of how the editor's account was compromised, because it's important to know whether or not thenextweb and other sites were compromised through a default-account-setting or because all of these sites happened to have an account with the same vulnerable password. Or did the hacker just attempt a brute attack against a huge swath of sites, and thenextweb and others were just a few that fell to it?
- tangue 15y agoMost of the compromised websites (if not all) are running on Wordpress...
- biased_observer 15y agoHow is this relevant? There are a huge number of WordPress sites. TNW use the word 'Hacked' like it took some level of skill and you end your line with ... which implies a weakness in the software. It is not the software here that is at fault. The lack of good information out of TNW along with the fairly ridiculous penultimate paragraph of drama would suggest it was them being lax with the security they had control of which caused this to happen.
- tangue 15y agoBy experience this kind of "attacks" are the results of : - Exploiting some Wordpress flaw - Social engineering - Weak passwords - Bruteforce Wordpress has a bad record on security http://packetstormsecurity.org/search/?q=Wordpress http://packetstormsecurity.org/search/?q=Wordpress , so yes, I'm implying a weakness in the software.
- biased_observer 15y agoYou give 4 reasons. Linking to a Packetstorm search does not show if core files are involved, if it is a plugin or if the report itself is invalid. The other 3 are not exclusive to WordPress. If you are right then each report on each site will tie it together. I say it will not because already you can see that no-one is pointing fingers at WordPress itself.
- dirkdk 15y agomy guess: first name of author, password or 123 as password
- bradmccarty 15y agoHis password was simple enough to be brute-forced.
- thenextcorner 15y agoor he might have been writing an article in a Starbucks working on an open wifi. Anybody who has Wireshark installed can go fish for passwords and other log in credentials in your local Starbucks! When will people learn that an open Wifi is not secure! (not claiming this is what actually happened here!)
- bproper 15y agoHe targeted high profile tech sites running Wordpress, for the most part, so my guess would be a WP vulnerability.
- InfinityX0 15y agoOther sites also impacted not listed on SEOmoz: http://psd.tutsplus.com/tutorials/tools-tips/hdr-photography/ http://psd.tutsplus.com/tutorials/tools-tips/hdr-photography... http://freelancefolder.com/5-tricks-that-make-you-more-attractive-to-clients/ http://freelancefolder.com/5-tricks-that-make-you-more-attra... http://www.webpronews.com/google-panda-update-2011-05 http://www.webpronews.com/google-panda-update-2011-05 I found these through a fresher data source than SEOmoz. There may be more impacted (and might show what the security flaw is to someone more sophisticated than me).