{"id":92,"date":"2005-10-04T14:39:37","date_gmt":"2005-10-04T13:39:37","guid":{"rendered":"http:\/\/www.odrakir.com\/blog\/?p=92"},"modified":"2005-12-05T02:17:18","modified_gmt":"2005-12-05T02:17:18","slug":"mozilla-hacked-again","status":"publish","type":"post","link":"https:\/\/www.odrakir.com\/blog\/2005\/10\/04\/mozilla-hacked-again\/","title":{"rendered":"Mozilla Hacked&#8230; again!"},"content":{"rendered":"<p>I just got this wonderful email from Mozilla:<\/p>\n<blockquote><p>The Spread Firefox Team became aware this week that the server hosting<br \/>\nSpread Firefox, our community marketing site, has been accessed by<br \/>\nunknown remote attackers who attempted to exploit a security<br \/>\nvulnerability in TWiki software installed on the server.  The TWiki<br \/>\nsoftware was disabled as soon as we were aware of the attempts to access<br \/>\nSpreadFirefox.com.  This exploit was limited to SpreadFirefox.com and<br \/>\ndid not affect mozilla.org web sites or Mozilla software.<\/p>\n<p>We have scanned Spread Firefox servers and at this time do not believe<br \/>\nany sensitive data was taken, but as a precautionary measure we have<br \/>\nshutdown the site and will be rebuilding the web site from scratch.  We<br \/>\nalso recommend that you change your Spread Firefox password and the<br \/>\npassword of any accounts where you use the same password as your Spread<br \/>\nFirefox account.  We will notify you again when the site is back up with<br \/>\ninstructions on how to change your password. (Note: We do use MD5<br \/>\nhashing on the passwords, but MD5 cannot protect all passwords against<br \/>\noff-line dictionary style attacks.)<\/p>\n<p>After Spread Firefox was compromised in July, we instituted procedures<br \/>\nto ensure that we apply all security fixes to the software running the<br \/>\nsite (Drupal and PHP) as soon as they become available.  Unfortunately,<br \/>\nthose procedures overlooked the installation of the TWiki software since<br \/>\nit is not used by the main Spread Firefox site.  When the system is<br \/>\nrebuilt, all the software will be audited to ensure that security<br \/>\nupdates will be applied in a timely manner.  We deeply regret this<br \/>\nincident and any inconvenience this may have caused you. Sincerely,<\/p>\n<p>Spread Firefox Team<br \/>\nMozilla Foundation\n<\/p><\/blockquote>\n<p>Nice&#8230; very nice.<\/p>\n<p>[tags]Mozilla, Firefox, Hacking[\/tags]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I just got this wonderful email from Mozilla: The Spread Firefox Team became aware this week that the server hosting Spread Firefox, our community marketing site, has been accessed by unknown remote attackers who attempted to exploit a security vulnerability in TWiki software installed on the server. The TWiki software was disabled as soon as [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[2,11,8],"tags":[],"class_list":["post-92","post","type-post","status-publish","format-standard","hentry","category-computer-stuff","category-personal","category-security"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/www.odrakir.com\/blog\/wp-json\/wp\/v2\/posts\/92","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.odrakir.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.odrakir.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.odrakir.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.odrakir.com\/blog\/wp-json\/wp\/v2\/comments?post=92"}],"version-history":[{"count":0,"href":"https:\/\/www.odrakir.com\/blog\/wp-json\/wp\/v2\/posts\/92\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.odrakir.com\/blog\/wp-json\/wp\/v2\/media?parent=92"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.odrakir.com\/blog\/wp-json\/wp\/v2\/categories?post=92"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.odrakir.com\/blog\/wp-json\/wp\/v2\/tags?post=92"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}