Slashdot Mirror


That North Korean Facebook Clone Has Already Been Hacked (vice.com)

Remember yesterday's story about an off-the-shelf Facebook clone in North Korea? Within a few hours that site was hacked by an 18-year-old college student in Scotland. An anonymous reader writes: Using the default credentials, Andrew McKean posted "Uh, I didn't create this site just found the login" in the site's box for Sponsored links. "McKean was able to become an admin for the site just by clicking on the 'Admin' link at the bottom of the site and guessing the username and password," writes Motherboard, which adds that the password was "password". McKean says the breach "was easy enough," and granted him the ability to "delete and suspend users, change the site's name, censor certain words and manage the eventual ads, and see everyone's emails."
The teenager said he had "no plans" for the compromised site -- except possibly redirecting it to an anti-North Korean page.

84 comments

  1. That's the best you could think of? by K.+S.+Kyosuke · · Score: 1, Troll

    "Uh, I didn't create this site just found the login"

    Why not "Kim Jong-Un is a pussy! Sincerely yours, Park Geun-hye" or something more creative like that?

    --
    Ezekiel 23:20
    1. Re:That's the best you could think of? by Anonymous Coward · · Score: 1

      Nah, you should be able to do better than that: Public Announcement: Following up on the policy of acceptable haircuts for students that need to follow the impeccable style of our beloved leader, we've decided to extend the required complance: Please report ot the nearest hospital for cosmetic surgery if your penis measures more than 2 inches to follow our beloved leaders standard.

    2. Re:That's the best you could think of? by Opportunist · · Score: 2

      How uninspired. The true gold would be:

      1. Make a few insanely absurd new rules for the North Korean people. This is actually the challenging part for a people that already had mandatory haircuts, I agree.
      2. Point a few western news networks at the page.
      3. Watch the ensuing hilarity when they start gobbling up your insanity as reality.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  2. Hacked? Really? by Frosty+Piss · · Score: 4, Insightful

    The word "hacked" is overused. Making a fairly easy assumption that the default UID / PID has not been changed by some rube North Koreans who didbn't expect anyone to notice the demo site is hardly a "hack".

    On the other hand, I'll bet that the REAL North Korean intel guys gathered a whole lot of data from the honeypot site.

    --
    If you want news from today, you have to come back tomorrow.
    1. Re:Hacked? Really? by Anonymous Coward · · Score: 0

      Oh yeah?! Well honey isn't vegan and pot is illegal! What do you say about THAT?

    2. Re:Hacked? Really? by thegarbz · · Score: 1

      The word "hacked" is overused.

      That's only because the bar for people is set too low. Hack means to gain unauthorised access to a system. Whether that was via a SQL injection or because someone gave up the password in a phishing scam, or someone unauthorised simply guessed the password isn't part of the definition.

      It was a cheap hack which required no skill what so ever, but a hack none the less.

    3. Re:Hacked? Really? by AmiMoJo · · Score: 1

      Yep. It's either a honeypot trap that this guy just stumbled into, or it's some random student's university project and pretty far from the spectacular "hack" that TFA seems to think it is. How many people are actually using this site and are they posting anything interesting?

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    4. Re:Hacked? Really? by turbidostato · · Score: 1

      "The word "hacked" is overused."

      Still, if this was not a North Korean site but, say, a US Gov one, wouldn't this boy be already assaulted by a SWAT team, moved to gitmo and presented as public enemy number one?

      Why the double standard?

    5. Re:Hacked? Really? by turbidostato · · Score: 4, Insightful

      "Hack means to gain unauthorised access to a system."

      That's a crack.

      A hack is any clever and usually unexpected use of technology to accomplish a task.

    6. Re:Hacked? Really? by JustAnotherOldGuy · · Score: 1

      Agreed...this is not really worthy of the "hacked" label.

      To call this "hacking" is akin to microwaving a burrito and calling it "cooking".

      --
      Just cruising through this digital world at 33 1/3 rpm...
    7. Re:Hacked? Really? by Anonymous Coward · · Score: 0

      The best definition I've heard is that a hack is using something for a purpose it was not originally intended for. That purpose can be, but not necessarily is malicious.

    8. Re:Hacked? Really? by thegarbz · · Score: 1

      That was a crack. Language has moved on and left the old definitions in the past. That's the upside and the downside of English and while you like the distinction if you tell someone you cracked a system they will likely think you're inhaling a new kind of drug.

    9. Re:Hacked? Really? by turbidostato · · Score: 1

      "That was a crack. Language has moved on and left the old definitions in the past."

      Only it has not moved. When a comment in code reads " # dirty hack: I did this because... " nobody thinks the author left a backdoor in the program.

    10. Re:Hacked? Really? by Anonymous Coward · · Score: 0

      is the burrito cooked at the end of the process? if it is, how can the process of taking a burrito and making it a cooked burrito not be called cooking?

    11. Re:Hacked? Really? by thegarbz · · Score: 1

      Only it has not moved.

      I beg to differ, as do people who read newsspeak, read the internet, consume various forms of popular media, talk at the water cooler, and those who write dictionaries which document the present use of words. Note I said document. The dictionary does not define, it only documents the present popular usage and some nicer dictionaries give you a bit of history of the words too.

      To claim the distinction is to not move with the times which while you're right unfortunately makes you an "outcast" to the common usage. Not that this is a bad thing, its actually part of being intelligent, but there's no denying that the language in common use has well and truly moved on.

    12. Re:Hacked? Really? by turbidostato · · Score: 1

      I beg to differ, as do people who read newsspeak, read the internet"

      It's funny then, that just yesterday, in the most sold newspaper in my country (so, for the masses), the CEO of one of the biggest telcos in the world presented his newly appointed Chief Data Officer as the "most famous hacker in the country". You can bet he was not talking about somebody that illegally breaks into others' systems.

    13. Re:Hacked? Really? by mcswell · · Score: 1

      Polysemy.

  3. Hacked by Anonymous Coward · · Score: 1

    "which adds that the password was "password""

    He must have used a sophisticated brute force attack.

    1. Re:Hacked by Anonymous Coward · · Score: 0

      If your brute force succeeds on the first try, it's still brute force, no ?

    2. Re:Hacked by Anonymous Coward · · Score: 0

      I think that's called intimidation tactics.

    3. Re: Hacked by Anonymous Coward · · Score: 0

      No. This was pushing the unlocked door in.

  4. Link the front page to factnet.org by Anonymous Coward · · Score: 0

    And watch the Scientologists square off with the government of North Korea.

    I'll bring the popcorn....

    1. Re:Link the front page to factnet.org by Frosty+Piss · · Score: 1, Troll

      No one cares about your Scientology obsession, because no one cares about Scientology. If you were stupid enough to get sucked into it in the first place, you're still stupid.

      --
      If you want news from today, you have to come back tomorrow.
    2. Re: Link the front page to factnet.org by Anonymous Coward · · Score: 0

      Not just yet. I thingk tgey should redirect the tech support to Mormon chat online, complaint derpartment to Landover Baptist chat ajin to a Catholic vs WASP forum, and what should Jehova's Vitnesses be bressed with from Best Korea server?

  5. which cunry has more... by Anonymous Coward · · Score: 0

    I dunno who boasts more Chuck-len Norris-esque jokes, Scottlan or Bess Koreahhhhh? I would have sold admin access to someone who would write some embassy into North Korea like on the tip of their Waffelhotel or write some more unicorn layets around somewhere... you know, because tgey tend to claim fiction exaggerations as greatest propoanda peices. Then install System D on their server to really scare them.

  6. food not meds. by Anonymous Coward · · Score: 0

    Pot is an agriculture product, no different than hopps.

    1. Re: food not meds. by Anonymous Coward · · Score: 0

      Just like poppies. I think I'll go sell heroin to middle school kids.

    2. Re: food not meds. by Anonymous Coward · · Score: 0

      Sell them cannabis too so there can more evidence of one of the few substances on Earth with no lethal dose, even with kids.

    3. Re: food not meds. by Anonymous Coward · · Score: 0

      I call BS. there is a lethal dose. Even if the LD 50 is something like 2Kg/Kg, it still has a lethal dose (In this case, the case of death would be something like overeating or crushing, if you really did apply 2Kg/Kg. )

    4. Re: food not meds. by Anonymous Coward · · Score: 0

      You must be fun at parties.

    5. Re: food not meds. by Anonymous Coward · · Score: 0

      I call BS on your BS. How to take it all before having the best nap of your life? Be fucking practical, not stupid.

      More people have died on water overdoses, not even counting drownings, of course.

  7. Safety by Anonymous Coward · · Score: 0

    I'm not sure I'd put my real name on any sort of embarrassment to the North Koreans. They are rather unpredictable.

    1. Re:Safety by Anonymous Coward · · Score: 0

      I'm not sure I'd put my real name on any sort of embarrassment to the North Koreans. They are rather unpredictable.

      The human race as a whole is unpredictable. Anon for a reason.

    2. Re:Safety by Opportunist · · Score: 1

      As unpredictable as the average child with a water gun full of ink. Yes, in theory he could ruin your dress, but in the end he's more afraid of the spanking he'd get for it than you are about your suit.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    3. Re:Safety by Mr+D+from+63 · · Score: 2

      I'm not sure I'd put my real name on any sort of embarrassment to the North Koreans. They are rather unpredictable.

      I predict North Korea will have at least one less (living) IT staff members.

    4. Re: Safety by Anonymous Coward · · Score: 0

      Maybe 20 years ago.

  8. Next man up by Anonymous Coward · · Score: 2, Interesting

    The poor shlub who administers that site has probably already been executed.

  9. Lock him up! by Anonymous Coward · · Score: 0

    Doesn't matter what he did, you said "hacker". It's the law!

  10. Lock him up! by Anonymous Coward · · Score: 0

    Hopefully he will be extradited to face his punishment.

  11. The new generation by fred911 · · Score: 4, Funny

    "The teenager said he had "no plans" for the compromised site"

      Ah these young'ins, back in the day it would be goatse.cx 'ed or at the very minimum a penis bird!

      Jeeze what's this world become.

    --
    09 F9 11 02 9D 74 E3 5B - D8 41 56 C5 63 56 88 C0 45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
    1. Re:The new generation by Anonymous Coward · · Score: 0

      When talking about NK, perhaps his decision leads to the execution of the people in who created the Facebook clone.

    2. Re:The new generation by Gravis+Zero · · Score: 1

      "The teenager said he had "no plans" for the compromised site"

      [...]

        Jeeze what's this world become.

      hopefully, more civilized. previous generations are really trying hard to ruin what's left of the world.

      --
      Anons need not reply. Questions end with a question mark.
    3. Re:The new generation by Some+nick+or+other · · Score: 1

      I can think of something more useful. See if the site computer has a modem or phone connection or something, and then bridge over onto the Kwangmyong intranet. Port scan and download everything! ... although at dialup speeds, it would take a while.

    4. Re:The new generation by techno-vampire · · Score: 4, Interesting

      I think that if I managed to hijack a site in North Korea, I'd simply redirect it to a tourism site in South Korea to let the North Koreans get a look at how the other half lives.

      --
      Good, inexpensive web hosting
    5. Re:The new generation by thegarbz · · Score: 1

      hopefully, more civilized. previous generations are really trying hard to ruin what's left of the world.

      Wow, found the captain of the fun police.

    6. Re:The new generation by Opportunist · · Score: 1

      Linking to goatse? Why, it's North Korea, I'm pretty sure the page already showed a huge asshole on the front page.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    7. Re:The new generation by Anonymous Coward · · Score: 0

      North Korean internet is effectively a county wide LAN

    8. Re:The new generation by Anonymous Coward · · Score: 0

      Which shows you'd have no hope of hacking it unless they used password as the password. You'd need to host the propaganda images locally or the redirect would only work outside NK. It wouldn't be effective though since only the NK elite has Internet access, and they already know the average SK citizen has it better than the average NK citizen. Like their counterparts in other countries, they do not care about those suckers.

    9. Re:The new generation by Anonymous Coward · · Score: 0

      Actually, I've met a few North Korean expatriates, we asked one, "what was it that made you risk your life leaving NK?" The answer, "nail clippers". He was posted on the NK/SK border across from an SK soldier, the SK soldier dropper some nail clippers and didn't bother picking them up. It ate at him, " how could he just leave something so valuable on the ground?" That one incident was the first thing that helped undo the brain washing of s lifetime of propaganda and lies.

      I've heard other similar stories as well.
      I assume the poor bastards just actually believe the propaganda. I mean, especially when your family will be thrown in a prison camp if you're caught.

    10. Re:The new generation by Anonymous Coward · · Score: 0

      Yep, linking to external content would have no useful effect. If he had wanted to make an impact he could have posted content from some other anti-NK site. Maybe even linked it off one of the main page's links rather than on the front page itself to avoid detection for a while.

  12. totally called it by Gravis+Zero · · Score: 1

    seriously, this was an easily predicted outcome. PHP and security are at odds with each other.

    --
    Anons need not reply. Questions end with a question mark.
    1. Re:totally called it by Tablizer · · Score: 1

      What's the safe language then?

  13. It's North Korea by Anonymous Coward · · Score: 0

    So it's ok to be a virtual vandal in some cases?

  14. Password is in english? by Anonymous Coward · · Score: 0

    Shouldn't the password have been in Korean?

    And what "eventual ads?" Maybe propeganda, but in a true Communist country there are no billboards, TV ads, or on-line ads. People are directed to build things like this and the central government is supposed to provide what people in the West would buy (food, shelter, clothes). And bigger items get shared by the public.

    1. Re:Password is in english? by hcs_$reboot · · Score: 1

      Shouldn't the password have been in Korean?

      The guy pumped and untared a tar.gz he found on the Net somewhere in a "docs" folder. Probably from the billions available from the US. That happens all the time in Western countries, but since it's NK, that makes the news.

      --
      Slashdot, fix the reply notifications... You won't get away with it...
  15. They were lucky by ruir · · Score: 1

    sarcasm on: He could have changed the password, and then they would not know how to regain it back....

  16. Crime by Anonymous Coward · · Score: 2, Interesting

    I hope he is prosecuted to the full extent of the law both UK and NK, any propaganda induced biased against NK is not reason enough to commit a crime.

    1. Re:Crime by Noah+Haders · · Score: 1

      it's not a crime to hack the DPRK.

  17. NK U? by Tablizer · · Score: 1

    It was probably a student project, not a gov't sponsored site. I doubt the NK gov't gives a fuck.

  18. Still illegal. by Anonymous Coward · · Score: 0

    It's surprising that one would admit to a felony like that. It being in nk doesn't suspend law.

  19. In what language is "password" a secure password? by raymorris · · Score: 1, Interesting

    He got in because the password was left as "password". In what programming language is "password" a secure password?

    Having said that, ten years or fifteen ago PHP had serious security issues, given that it is designed to be used on web, where the application will be attacked daily. It was literally impossible to write a secure program in PHP; literally "hello world" had a security vulnerability. Much has changed. PHP was originally a CMS, written in Perl with a bit of C. It's now an actual programming language, one used by clueless little companies like Facebook. Seriously, it has improved a lot. The world's largest web sites wouldn't be running on PHP if it were junk.

    Having said THAT, it's still an "easy" language to start learning. You can start writing little PHP scripts without being trained and educated as a programmer. If you do that in any language and put your scripts on the web, you'll get hacked. While PHP as a language is pretty decent now, PHP "scripters" who don't know any programming language other than PHP are still mostly people who don't know much. But the same is true of .Net or many other languages. If you learned a bit of a language but never learned programming and especially security issues of web programming, you probably shouldn't expose your software to internet hackers.

  20. Non-story by Wuhao · · Score: 1

    This sounds like a default, or near-default install of a basic web application, made available from a public-facing IP. The only remotely interesting thing here is that the IP is in NK, but the only real story seems to be "someone in North Korea with the ability to allocate a public IP played with dolphinPHP." I mean, it could be an official party directive. Or it could be that some bureaucratic entity in DPRK did what bureaucratic entities love to do: had an idea that went nowhere, which may not have ever been understood by anyone in the first place, and led to some amount of useless effort being expended.

  21. Since when? by burni2 · · Score: 1

    1.) since when it is not a crime to hack DPRK, just because its the DPRK, I think the UK computer fraud acts are pretty specific.

    The big exception is, when you would be part of the military or part of a secret service - then you can commit crimes sometimes even against humanity and go unpunished.

    2.) And there might be an exception when the hacking could go unpunished, exactly if it would be used to save lifes, for example or stop attrocities (by changing the execution list for example), or bring evidence forth about violation of human rights.

    1. Re:Since when? by Noah+Haders · · Score: 1

      Who from the DPRK is going to press charges? That would make the Dear Leader look like a Deer Breeder. Also, what kind of jury would convict on something like that? Also, I'd like to see the evidence.

    2. Re:Since when? by Joe_Dragon · · Score: 1

      and if the DPRK fakes evidence or clams that the hacked killed someone then what?

    3. Re:Since when? by Noah+Haders · · Score: 1

      A gold medal.

    4. Re: Since when? by Anonymous Coward · · Score: 0

      So, is it not a crime, or just causes embarrassment?

      In other words, you don't know what the fuck you are talking about.

  22. Re:In what language is "password" a secure passwor by Anonymous Coward · · Score: 0
  23. the question is by Anonymous Coward · · Score: 0

    Will North Korea pursue this malignant hacker?

    1. Re:the question is by Anonymous Coward · · Score: 0

      Will North Korea pursue this malignant hacker?

      No, but maybe the Polis will pay this wee bampot a visit..

  24. Oh? This is a story now? by SeaFox · · Score: 1

    Kinda amused to see this get put out as a story now. It didn't get much attention when I pointed it out yesterday. The little ninja character was gone pretty fast, though.

  25. Re:In what language is "password" a secure passwor by Anonymous Coward · · Score: 0

    The world's largest web sites wouldn't be running on PHP if it were junk.

    Lol, I'm sure that's a logical fallacy.

    The only reason why Facebook is still using PHP is because they had too much legacy code. They had serious up-scaling issues a number of years ago, so they created their own "PHP", which is compiled and supports type checks. They also use extensive unit tests for every little bit of code, which is not how the typical PHP app is written.

    So is it possible to write (non trivial) secure code with modern PHP? Maybe, with a lot of effort and testing. But I wouldn't stake my life on it. Wordpress and Drupal get hacked all the time.

    Btw I'm maintaining/refactoring a large legacy PHP backend, so I'd like to think I know what I'm talking about. PHP is the only programming language I've used (of many) where WTF is the new normal...

  26. I don't get it. by hey! · · Score: 1

    Why is this news? Were people expecting North Korean admins of off-the-shelf websites to somehow be better than ones in the rest of the world?

    --
    Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
  27. Re:In what language is "password" a secure passwor by raymorris · · Score: 1

    >> Ten or fifteen years ago PHP sucked
    > I'm maintaining/refactoring a large legacy PHP

    I feel your pain. I've done the same with a million-line PHP project called Moodle.

        Since you are refactoring, I hope you study modern PHP and apply it where it makes sense.

  28. Re:In what language is "password" a secure passwor by jordanjay29 · · Score: 1

    Having used Moodle for a university class, I bow to your unholy patience and fortitude.

  29. Has it been changed yet?? by Anonymous Coward · · Score: 0

    I bet that the owner cannot or does not read this or any other tech news.

  30. Deathtoll ? by Thanatiel · · Score: 1

    How many North Corean people will die because of this ?
    Or is the crazyness not to that level yet ?

    --
    Irrelevant news and morons using moderation to mod down what they disagree on. 2018 resolution: so long.
    1. Re:Deathtoll ? by Anonymous Coward · · Score: 0

      That was my first thought also. Yes it is certainly at that level.

    2. Re:Deathtoll ? by Anonymous Coward · · Score: 0

      Was thinking the same thing, this Andrew McKean fellow probably just inadvertently got a whole bunch of people killed or sent to a prison camp, etc.

  31. Thoughtless youth by Anonymous Coward · · Score: 0

    This prank will probably cause the poor schmuck that is web admin for the site to literally lose his head.
    North Korea consists of 1 maniac leader, a handful of supplicant generals fearing for their lives, and millions of poor schmucks nearly starving to death while fearing for their lives.

  32. Re:In what language is "password" a secure passwor by Anonymous Coward · · Score: 0

    He got in because the password was left as "password". In what programming language is "password" a secure password?

    The password programming language of course. It is spelt pa55w0rd don't you know? Shame on you Mr. Morris. LOL

  33. An older vesion, I'm guessing by raymorris · · Score: 1

    I'm guessing you used an older version. Moodle too has improved dramatically in the last four years. It has really grown up.

  34. host a special election by Anonymous Coward · · Score: 0

    Powdered Toastman ftw!

  35. Dunno why... by Anonymous Coward · · Score: 0

    ...but some guy called Kim has the most friends.