Mozilla Hacked… again!

·

I just got this wonderful email from Mozilla:

The Spread Firefox Team became aware this week that the server hosting
Spread Firefox, our community marketing site, has been accessed by
unknown remote attackers who attempted to exploit a security
vulnerability in TWiki software installed on the server. The TWiki
software was disabled as soon as we were aware of the attempts to access
SpreadFirefox.com. This exploit was limited to SpreadFirefox.com and
did not affect mozilla.org web sites or Mozilla software.

We have scanned Spread Firefox servers and at this time do not believe
any sensitive data was taken, but as a precautionary measure we have
shutdown the site and will be rebuilding the web site from scratch. We
also recommend that you change your Spread Firefox password and the
password of any accounts where you use the same password as your Spread
Firefox account. We will notify you again when the site is back up with
instructions on how to change your password. (Note: We do use MD5
hashing on the passwords, but MD5 cannot protect all passwords against
off-line dictionary style attacks.)

After Spread Firefox was compromised in July, we instituted procedures
to ensure that we apply all security fixes to the software running the
site (Drupal and PHP) as soon as they become available. Unfortunately,
those procedures overlooked the installation of the TWiki software since
it is not used by the main Spread Firefox site. When the system is
rebuilt, all the software will be audited to ensure that security
updates will be applied in a timely manner. We deeply regret this
incident and any inconvenience this may have caused you. Sincerely,

Spread Firefox Team
Mozilla Foundation

Nice… very nice.

[tags]Mozilla, Firefox, Hacking[/tags]

Comments

3 responses to “Mozilla Hacked… again!”

  1. vd Avatar

    Parece-me um titulo demasiado ‘paragona’.
    O site mozilla.org continua o mesmo, o software também, o firefox either, mas o site spreadfirefox foi hackado. Dai a dizer que o Mozilla foi hackado novamente, vai uma distância bem grande.

  2. Pedro Teixeira Avatar
    Pedro Teixeira

    Concordo com o vd.
    Não caiam em tentação…
    Qualquer dia, se conseguirem entrar em casa de um colaborador da Mozilla Foundation, vão dizer “Mozilla Hacked…again!”… Por favor…

  3. Odrakir Avatar

    Sim, talvez não se deva julgar o todo pelas partes, mas em menos de 4 meses já é a segunda vez que um site da Mozilla é hackado. Penso que o importante aqui é o facto de ser um site que contem informação crítica e que pode constituir um risco para terceiros.

    “We have scanned Spread Firefox servers and at this time do not believe
    any sensitive data was taken, but as a precautionary measure we have
    shutdown the site and will be rebuilding the web site from scratch.”

    Este parágrafo não me dá segurança nenhuma, a Mozilla não me garante que a minha informação foi (ou não) vista/adquirida por quem não devia.

    Pessoalmente não tenho nada contra a Mozilla, sou utilizador dos produtos deles, mas começo seriamente a pensar em “dar a cara” por eles (como foi neste caso visto ser o Spread Firefox).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.