9 ms·
Skype blog hacked
- coffeecheque 13y agoIts Twitter account was also hacked and a message posted, but it appears to have been deleted. Screenshot here: https://twitter.com/MikeElgan/status/418482819611230208 https://twitter.com/MikeElgan/status/418482819611230208
- ehPReth 13y agoLooks to be one of those auto posters (i.e. content posted on the blog is automatically pushed out to twitter, facebook, others)
- ihatehandles 13y agoI thought so as well, until https://twitter.com/Skype/statuses/4184954534710681 https://twitter.com/Skype/statuses/4184954534710681
- ehPReth 13y agoAhh, I see. Interesting!
- t0 13y agoMore than likely a guessed admin password.
- xSwag 13y agoThis blog is not hosted by the Skype but on WordPress VIP. This means that, most likely, the blog was not broken into using a software exploit of any sort since the security on VIP blogs is professional. Knowing that this is the Syrian Army, this attack was most likely done using phished credentials. If they had any sort of system access they would have defaced the entire subdomain or the main site. So most likely, this is nothing to worry about. Your account data most likely still in safe hands.
- t0 13y agoYou're right. It was probably a brute force since they don't have maximum login attempts. http://blogs.skype.com/wp-admin http://blogs.skype.com/wp-admin
- elwell 13y agoSuch a simple feature to implement...
- devinegan 13y agoIt does appear to be a brute force or phishing attack. These sort of drive-bys can typically be permanently stopped with 2FA or a password-less MFA solution like LaunchKey (Disclaimer: co-founder). LaunchKey has a free WordPress Plugin available, among others: http://wordpress.org/plugins/launchkey/ http://wordpress.org/plugins/launchkey/ It is 2014, you better prepare a good PR response for when you get breached OR start implementing stronger authentication ASAP.
- Ergomane 13y agoIt is only a simple feature if you don't care about DOS against the user account and do not have an adversary with a large botnet.
- Viper007Bond 13y agoLimiting login attempts is not as effective as you might think. How should it work? If you want to ban IP addresses that get X attempts wrong in Y minutes, then you're failing to realize that hackers like this normally have access to hundreds or thousands of IP addresses. If you want to lock the whole account for a while, then you've just introduced a way for anyone to lock the account of someone else they don't like. Also considering that their Twitter and Facebook accounts were also compromised, your assumption that it was the blog itself that was compromised is a big one. I don't have any first hand knowledge on that though personally, I'm just saying.
- Spearchucker 13y ago
- lelandbatey 13y agoHere's a screenshot of the blog, in case it get's fixed: http://puu.sh/65TRe.png http://puu.sh/65TRe.png
- tsurantino 13y agoThey also hacked their Facebook page.
- romanovcode 13y agoI'm not sure why the accent on "Stop using MS, it's spying on you!" is on MS. AFAIK every company is using your data and giving/selling it to the government. How is MS more evil than anyone else?
- zeitg3ist 13y agoMicrosoft has been moving Skype from its original peer-to-peer architecture to a more centralized system for some time. After the Snowden shitstorm, critics have been implying that the move was NSA-related.
- magic_haze 13y agoI might be wrong, but wasn't skype's p2p system used mostly for udp hole punching? (i.e., the supernodes were used to initiate the connection and then the clients communicated directly with each other.) With the centralized system, do the call contents go through microsoft's servers now? (this should be pretty easy to prove, doesn't it? Just check the addresses where your UDP packets are being sent to and received from.) It just seems to me that if anyone wanted to spy on you, forcing someone else to migrate to an entirely new system would be massive overkill: Applebaum's talk shows there are _plenty_ of better tools available to get to your packets. EDIT: This really seems like an interesting question: _are_ there any advantages an attacker would have with skype's centralized system that they wouldn't with their previous p2p system? From what we've seen so far, I think the differences (from an attacker's perspective) are trivial.
- RyanZAG 13y agoIf someone drowns 4 kittens and you only drown 1 kitten, you're still pretty evil. I don't see how "everyone else is doing it" is possibly a valid argument. Obviously 'evil' in this case is based on your definition though, it's not exactly a universal concept.
- diminoten 13y agoWhat if a cop held a gun to your head and told you to drown those kittens?
- mrkris 13y agoI don't consider getting access to a website via the most insecure blogging platform on the internet "hacking".
- thirsteh 13y ago[citation needed] WordPress isn't that insecure. A lot of third-party (i.e. written by inexperienced developers) plugins for it are, though.
- jblz 13y agoNot sure why you say that. WordPress.com offers 2-Factor Auth: http://en.support.wordpress.com/security/two-step-authentication/ http://en.support.wordpress.com/security/two-step-authentica... There are also tons of available security plugins & pretty extensive documentation on hardening a self-hosted install: http://wordpress.org/plugins/tags/security http://wordpress.org/plugins/tags/security http://codex.wordpress.org/Hardening_WordPress http://codex.wordpress.org/Hardening_WordPress
- krapp 13y agoStill, a lot of what's on that page and a lot of the common features of plugins like Wordfence (which I use) should be part of the core, I think. Though also in my opinion even having a web-based file editor is pretty terrible...
- X4 13y agoHardening Wordpress. That made me speechless………… But hey, what do I know? ¯\_(ツ)_/¯ Only the tip of the iceberg. Some men believe. https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=wordpress https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=wordpress
- krapp 13y agoHow much of what's on that list actually applies to a recent version of Wordpress?
- deleted 13y ago[deleted]
- yeukhon 13y agoHere is the screenshot of the blog hacked. http://imgur.com/RGeTFWV http://imgur.com/RGeTFWV So it looks like Skype doesn't host on its own server. It looks like this is wordpress.com but with custom domain? curl http://blogs.skype.com http://blogs.skype.com -v < X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. EDIT Okay it is New to wpscan. When it says plugins found are these the vulnerable plugins wordpress.com running? https://gist.github.com/yeukhon/8211580 https://gist.github.com/yeukhon/8211580 And I found the username 7 pretty interesting.... wonder if I am actually doing the ethical thing here :(
- xsNzgw8 13y agoYou will find those usernames whenever you scan wordpress.com with wpscan.
- rev087 13y agoThere is also a second post from the same - apparently compromised - author: http://blogs.skype.com/2014/01/01/dont-use-microsoft-emails-hotmailoutlook-they-are-monitoring-your-accounts-and-selling-the-data-to-the-governments/ http://blogs.skype.com/2014/01/01/dont-use-microsoft-emails-...
- deleted 13y ago[deleted]
- xsNzgw8 13y agoSnapshot archive (if they fix the page): http://mraka.eu/snapshot/v/blogs.skype.com http://mraka.eu/snapshot/v/blogs.skype.com Direct link to the snapshot of the hacked site: http://mraka.eu/snapshot/img/2014/01/01/e0d8888c73483275afea3ba8e007adaf.png http://mraka.eu/snapshot/img/2014/01/01/e0d8888c73483275afea... Snapshot archive of twitter account: http://mraka.eu/snapshot/v/twitter.com http://mraka.eu/snapshot/v/twitter.com Direct link to the first tweet snapshot: http://mraka.eu/snapshot/img/2014/01/01/1d6269aa8371ce67658770d5d703e2d9.png http://mraka.eu/snapshot/img/2014/01/01/1d6269aa8371ce676587... Direct link to the first retweet snapshot: http://mraka.eu/snapshot/img/2014/01/01/a0f4c0947281bb0fb19dce9a1a74b750.png http://mraka.eu/snapshot/img/2014/01/01/a0f4c0947281bb0fb19d...
- wahnfrieden 13y agoThe Twitter account has also been compromised at the same time: https://news.ycombinator.com/item?id=6996899 https://news.ycombinator.com/item?id=6996899
- ihatehandles 13y agoGotta wonder what's running through non-techie Skypers when they see the tweets (https://twitter.com/Skype/status/418495453471068161 https://twitter.com/Skype/status/418495453471068161) and all :D
- ollysb 13y ago>> Hacked by Syrian Electronic Army.. Stop spying! Seems a strange message to send to a country that spies on it's own citizens (and where apparently the citizens are unable to prevent their own government from doing it to them).
- X4 13y agoIndeed and they buy german spying technology products. However I think the logical fallacy you've stepped in is that the Syrian Electronic Army (SEA) doesn't want to get spied on themselves by Skype and Microsoft, maybe. haha :) But I fully support the message here, I think that spying inside of consumer products is a sign of the abuse of power and monopoly.