Ubuntu Forums are back up and a post mortem
blog.canonical.com
blog.canonical.com
Terrible. Why even allow this. A terrible, horrible cludgy hack.
I know that DB-level and web-server-level intrusion detection systems exist - can the HN community comment on what might have detected this particular attack (even if only after-the-fact?).
>> They used this access to download the ‘user’ table which
>> contained usernames, email addresses and salted and hashed
>> (using md5) passwords for 1.82 million users.
Somewhere, oclHashcat makes room temperature rise.