MacRumors live feed hacked during keynote
macrumorslive.com
macrumorslive.com
Pretty interesting to watch it unfold. The first SQL the guy posts is a SQL injection waiting to happen:
$query = "select * from sms_users where authentication='".$_GET["auth"]."'";
Edit: Changed link to use webcitation because 4chan link went down. Original link was at: http://zip.4chan.org/g/res/3118906.html
http://img.skitch.com/20090106-p2dughwb2yujxdutfh55ixxajn.pn...
My first guess was http://macrumorslive.com/admin which contained the full source code and password hashes to everything on the site.
They must have had a strange configuration because their .php files were showing as plain text files. This revealed their master DB username/password along with many other ways to exploit the site.
There's a reason security through obscurity doesn't work. Unfortunately MacRumors had to find out on what was probably their biggest day of the year.
The even worse part is, it isn't even obscure! The path is /admin/ not /walrus/ or something. And why would they have plain-text php files at that URL? It's like shooting yourself in the foot and lighting yourself on fire in a bear pit at the same time.
May I guess unprotected admin panel, like Tumblr and Twitter?
another screen shot.
According to #macrumorschat, some 4chan kids figured out that going to macrumorslive.com/admin showed the source code, and that's how they figured out how to inject their own text.
It really sucks for the MacRumors guys since this is probably their biggest ad revenue day of the year.
edit: I see, MacRumors was hacked. n/m then.