TechCrunch Hacked
techcrunch.com
techcrunch.com
For when this gets fixed, right now techcrunch.com is an empty html page that contains <a href="http://nottherealurl.com/ title="rapidshare downloads">rapidshare downloads</a>
Edit: now it is a blank html page that contains only "hi". Someone from HN rehacked it? Or it's about to be fixed.
Just as most new web sites are not startup companies, most existing web sites are not apps.
The distinction and difference is that a software application helps a user perform manipulation or transformation of data as useful work.
Most websites, despite simple interactivity (e.g. search), are still published as "content" for consumption within a content access application, not for manipulating work|play|creative output.
The html: <title>LOL HACKED</title>
<center><h1><b>WHAT A FUCKING USELESS HACK ISN'T IT? BLEH.</b></h1></center><br>
<h1><a href="http://dupedb.com/ title="rapidshare downloads">http://dupedb.com/</a></h1><br>;
(Yes, my blog is currently hosted at wordpress.com, but I'm evaluating Jekyll as part of the next round of server migrations. I started with wordpress.com years ago when I didn't want to run WP on my own server, but wanted the ease of a blog.)
Will be interesting to hear the details. TC has done a lot to secure their site, but they were using WordPress.
If you can place a .php file in the plugins directory located here: http://www.techcrunch.com/plugins/
And then if you call the script as per your example, then it appears that plugin is loaded (and evaluated).
Someone else more versed in PHP might want to cast their eyes over the wordpress plugin to see whether I'm right: http://wordpress.org/extend/plugins/wp-super-cache/
But it appears it's a case of globals not being checked prior to use: http://php.net/manual/en/security.globals.php
So at first glance and with limited info... it's a plugin. Not that this surprises me, I still use vBulletin and I spend a lot of time code-reading the plugins for that before I use them. Mostly to make sure they don't do silly things like have SQL inside a loop over potentially lots of items, but also for the obvious security holes.
register_globals is an old one though, should be disabled: http://drupal.org/node/222343
I hope they go for the radical openness option and do a full public post-mortem. A teachable moment like this should not be wasted.
register_globals was known to be a bad idea in 1999 for crying out loud.
There's not even a valid reason to turn that setting on, with legacy not even being an excuse.
Huh? How does "big" make them deserve a custom solution? Huge behemoths like nowPublic.com and spreadfirefox.com run Drupal. Heck, economist.com is >>> techcrunch, and they're dropping their custom solution and shifting to Drupal. IMO, "big" is the least of their concerns if they want to switch to Drupal. TC is perfect example of a website wanting content management. Content is what they deal with.
But, I will say Drupal is not the answer to all problems. For example: if your application deals primarily with data that can't be classified broadly into "content". Like last.fm or chesspark.com or etherpad.com... you get me.
Wrong.
http://siteanalytics.compete.com/techcrunch.com+economist.co...
Page views alone aren't that big a deal in a content website like TC/Econ - you can do plenty of caching, buy more servers etc. Serving the needs of all the various people involved in an Economist-type publication is where the challenge is.
-Unfortunately responsible for maintaining a Drupal install at work...
Similarly a term such as "killer" may have an extremely negative connotation in the context of a grisly homicide yet the same word may have a positive connotation and a completely different meaning (dominant, superlative, desirable) in other connotations. Such is the dynamic, flexible, and adaptive nature of language (outside the realm of the pedant).
1 : one that hacks 2 : a person who is inexperienced or unskilled at a particular activity <a tennis hacker> 3 : an expert at programming and solving problems with a computer 4 : a person who illegally gains access to and sometimes tampers with information in a computer system
Three out of four possible Merriam-Webster definitions are negative.
Apparently few Apache 1.x installations use to send this header as part of some fix for few versions Netscape.
Edit: TC seems to acknowledge the hack now. Also, the header X-Pad is missing now.
"Earlier tonight techcrunch.com was compromised by a security exploit.
We're working to identify the exploit and will bring the site back online shortly."
Surely that's the case every day???
LMFAO
Someone needs to find a sense of humor.
but i feel the hack was done today instead of tomorrow to let them know the hackers displeasure on something. but not to really hit them when it matters... (which is tomorrow for apple presentations )
maybe its just a warning perhaps.
I am sure techcrunch is working on this...
wordpress systems are pretty stable but all systems have a loophole.. on many systems, you can't avoid the hacking because it is the human errors (or negligence)
Now, how long til we get Arrington's spin?
That’s why covering all angles is important…
--dd http://sucuri.net