iTunes Music Store Hole Discovered, Patched
prockcore writes "A vulnerability has been found in Apple's iTunes Music Store. The flaw enabled hackers to hijack other people's accounts by knowing only their email address, and download music with it. Apple has patched the hole."
I'm glad to hear that the Canadian Researcher didn't exploit the hole and no one (so far) has been bit in the ass by the error. This is how to handle vulnerabilities IMHO.
Now we know where those huge amounts of downloads are coming from :)
maybe they should have used a worm to penetrate the apple..
Just wait until Microsoft copies this service.
--- Jason Olshefsky
Karma: Poser (mostly affected by adding this line long after everyone else did)
How does something as simple as not passing authentication objects/info to the browser get past Apple's QA? Session Objects, Cookies and Hidden form fields are never secure from the user. Amazing this still happens.
Ah, it feels like 1996 again.
s/hackers/jackasses who think it's cool to defraud and steal, and make the rest of real hackerdom look bad.
jX [ Make everything as simple as possible, but no simpler. - Einstein ]
After logging in as madonna@imabitch.com, it was great. You wouldn't believe all the music that girl ownz.
I like how wired gave a (fairly) detailed description of the problem.. but no detailed description of the FIX.. so is this problem "really" fixed?
risk area, where if you and QA don't catch something like this, you're fired.
It makes you code better knowing screwing up could cost you your job. Although in situations like that you usually get more realistic development schedules compared to the corporate schedule of get it done now. (Or at least that's what I've experienced.)
direct download links are better! heheh...check out earth2willi.com for lots of free music downloads to install on your new iPod! It's registration and advertisement free, untouched by the RIAA, available in various genre and fileformats, complete with print resolution artwork, and uncrippled by DRM.
I find it very funny that there's only been like 23 posts on this topic. If it was Windows or IIS or something, there'd be like 500 minimum.
I am a homosexual. I bought an Apple computer because of its well earned reputation for being "the" gay computer. Since I have become an Apple owner, I have been exposed to a whole new world of gay friends. It is really a pleasure to meet and compute with other homos such as myself. I plan on using my new Apple computer as a way to entice and recruit young schoolboys into the homosexual lifestyle; it would be so helpful if you could produce more software which would appeal to young boys. Thanks in advance.
with much gayness,
Father Randy "Pudge" O'Day, S.J.
Thanks for your letter. Being Catholic myself, I know exactly what you're talking about! It has always been our plan here at Apple Computer Inc to revolutionize personal computing with our high-quality and highly gay products.
I'm happy to answer your letter by letting you know that YES we will be releasing an entire hLife ("homo-life") software line. You'll be able to recognize it in stores by the small stylized logo depicting a large cock entering a tight anus with an Apple logo on it. ("Suddenly it all comes together" indeed!).
Anyway, I hope you and other members of our community will join us on our mission, and purchase the exciting new hLife boxed set. Only the boxed set comes with translucent cock rings!
Sincerely,
Harry Rodman
Vice-president
Homosexual Liaison Services
Apple Computer, Inc.