Results 1 to 9 of 9

Thread: We've been hacked :roll:

  1. #1
    Former lead dev Nick's Avatar
    Join Date
    Jun 2009
    Location
    Kakamigahara, Japan
    Posts
    2,869
    Blog Entries
    88
    Thanks
    482
    Thanked 806 Times in 526 Posts

    Default We've been hacked :roll:

    Looks like we have ruffled some feathers because the folk from Pligg decided to hack into our demo site and renamed it "Pligg Rulez"!

    We're an open source project and as such, our code is publicly available for all to see, which does leave us vulnerable to hackers. Still, that's half the fun of open source programming, and getting a friendly nudge like this from our friends at Pligg is a reminder that we need to pay more attention to security issues.

  2. #2
    Admin & Design JonH's Avatar
    Join Date
    Jun 2009
    Location
    New Braunfels, Texas
    Posts
    248
    Thanks
    57
    Thanked 49 Times in 30 Posts

    Default

    Good to see Hotaru news is getting around

  3. #3
    Design & Development carlo75's Avatar
    Join Date
    Oct 2009
    Location
    Italy - Perugia
    Posts
    509
    Thanks
    62
    Thanked 105 Times in 58 Posts

    Default

    Unfair... pligg don't rules!

  4. #4
    Design & Development carlo75's Avatar
    Join Date
    Oct 2009
    Location
    Italy - Perugia
    Posts
    509
    Thanks
    62
    Thanked 105 Times in 58 Posts

    Default

    Do you know how they do that?

  5. #5
    Former lead dev Nick's Avatar
    Join Date
    Jun 2009
    Location
    Kakamigahara, Japan
    Posts
    2,869
    Blog Entries
    88
    Thanks
    482
    Thanked 806 Times in 526 Posts

    Default

    Quote Originally Posted by carlo75 View Post
    Do you know how they do that?
    I can't say for sure, but it would have been possible with a cross-site request forgery - probably on the user permissions page to get admin access. I'll go through every form, adding tokens with this CSRF Protection Class, and then maybe they'll be kind enough to try and hack us again so we can see if it worked.

  6. #6
    Junior Member
    Join Date
    Oct 2009
    Posts
    6
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    hahaha Nick your comments are amusing, thanks for the laugh

    We all see great potential in Hotaru and apparently so do the folks at Pligg.com. Quiet frankly, if it wasn't for them, Hotaru wouldn't be here. This is a good example of when developers care more for making money via Plug-gins than providing quality and support. This is just my personal opinion based on experience.

    Thanks Pligg!

  7. #7
    Senior Member rushnp774's Avatar
    Join Date
    Nov 2009
    Location
    Lees Summit, MO
    Posts
    142
    Blog Entries
    2
    Thanks
    14
    Thanked 10 Times in 6 Posts

    Default

    No wonder you've been going balls-to-the-wall with the CSRF stuff lately Nick. Makes sense . Hopefully that was how they did it, and that your changes will block it next time. If it wasn't how they hacked it, we're (hopefully) protected against CSRF in the future, so it's all good.

  8. #8
    Member
    Join Date
    Sep 2009
    Posts
    35
    Thanks
    5
    Thanked 0 Times in 0 Posts

    Default

    I read pligg status update. They claim to have nothing to do with the attack.

  9. #9
    Former lead dev Nick's Avatar
    Join Date
    Jun 2009
    Location
    Kakamigahara, Japan
    Posts
    2,869
    Blog Entries
    88
    Thanks
    482
    Thanked 806 Times in 526 Posts

    Default

    Quote Originally Posted by bbrian017 View Post
    I read pligg status update. They claim to have nothing to do with the attack.
    Well that rules out all 50,000 Pligg users then. Phew!

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •