Details of the LiveJournal Account Hacks
An anonymous reader writes "Brian Krebs of the Washington Post has written about the recent spate of
hijackings at Six Apart's popular LiveJournal service. Hundreds of journals have now been taken over by a
notorious group called 'Bantown' using a series of complicated cross-site-scripting vulnerabilities. Krebs details the recent security changes made by LiveJournal in response to the takeovers." From the article: "It is unclear whether LiveJournal has managed to close the security holes that the hackers claim to have used. The company says it has, but the hackers insist there are still at least 16 other similar JavaScript flaws on the LiveJournal site that could be used conduct the same attack. [Bantown] group members said they plan to turn their attention to looking for similar flaws at another large social-networking site. "
Maybe they should write about how they did it in their blog, I mean someone elses blog.....
How on Earth are all those white kids in the suburbs going to express their teen angst now?
I've seen your pictures and can definitively say that the hackers were doing the world a service.
This guy's the limit!
I can just see them shivering in a cold, dank corner, cutting themselves because their journal was hi-jacked.
No, they wouldn't. Because there's no longer a reason to cut themselves! No one can read or comment about it.
They also don't tell us which browser is affected on the newspost. How can we be safe if we are not informed? Can Six Apart actually deal with this in a professional way? I've been noticing LiveJournal is really slow and it hangs a lot lately. It seems that they know nothing about security and are just randomly mashing buttons in a attempt to hit the nail in the head.
Is Six Apart that incompetent that they can't prevent such attacks after they have been going for days, or is this bantown group really that good?
Bored? Browse Slashdot with a +6 modifier for Troll comme
...they hacked into my LJ and corrected all the meter in my "I am sad/I want to die" goth poetry!
"Made up/misattributed quote that makes me look smart. I am on
Current mood: 0wned
I am officially gone from
<Pax> I wish my lawn was emo, so it would cut itself.
I think we can keep recursing like this until someone returns 1
When your site is down & Livejournal's making you angry
You can always blame - Bantown!
When you've got blogs, all the noise and the worry
Seems to stop, I know - Bantown!
Just listen to the music of the vulnerable website
Linger on the domain where the CSS is not right
You only lose!
The lags are much longer there
You can see all your troubles, see all your fear
So go Bantown! things'll be worse when you're
Bantown! - no security measures, for sure
Bantown! - everyone's waiting on you!
He who knows best knows how little he knows. - Thomas Jefferson
I've written an FAQ on this type of attack which can be found below.
The Cross Site Scripting FAQ
Believe me, if I started murdering people, there would be none of you left.