furrbear: (Body Count)
[personal profile] furrbear
As a CS geek with an interest in security...

BanTown via a scripting hack. Impressive even though outrage inducing.

Tom Maher, [livejournal.com profile] tmaher, explains it in layman terms.

A few more links:
http://tehdely.livejournal.com/88823.html

http://community.livejournal.com/brutal_honesty/3168992.html

http://pastebin.ca/1390576
The description from the guy claiming responsibility seems totally plausible. I wonder when it will be used against another site with some form of "Report Objectionable Content" system; e.g., YouTube. It apparently was already used against Livejournal (The Great Strikethrough).

Date: 2009-04-13 10:09 pm (UTC)
From: [identity profile] robearal.livejournal.com
It doesn't completely explain issues occurring since February.

Date: 2009-04-13 10:26 pm (UTC)
From: [identity profile] tbass.livejournal.com
As someone who used to "hack" all sorts of stupid websites when I was younger, I can definitely see that as a valid thing that could have happened and was actually one of my first thoughts when I heard about the whole Amazon thing. Although, I'd assumed it was some relgious nut.. not some random bored guy who was pissed about craigslist.

Date: 2009-04-13 10:43 pm (UTC)
From: [identity profile] sultmhoor.livejournal.com
Yeah, don't automatically believe his posted reasons. Doin' it for the lulz is enough motivation. ;)

Date: 2009-04-13 10:46 pm (UTC)
From: [identity profile] furrbear.livejournal.com
Sure it does. Development work. One or two books to make sure it all works.

Date: 2009-04-13 10:48 pm (UTC)
From: [identity profile] sultmhoor.livejournal.com
Embedding in iframes/images for cross site credential exploitation is exactly how to fuck with bear411, too. ;)

Date: 2009-04-13 10:53 pm (UTC)
From: [identity profile] jediknightcub.livejournal.com
Thanks for the heads-up.

Coincidentally, [livejournal.com profile] cuchulainmacog just asked me why people would create viruses. I told him, "To show exploits and weaknesses in operating systems and software. It's not the most admirable thing to spend one's time doing, but it does point out security flaws and exploits and forces the company to immediately deal with whatever issue is currently the focus of the day's news cycle.

Date: 2009-04-13 10:54 pm (UTC)
From: [identity profile] furrbear.livejournal.com
EXACTLY! iframe/image XSS is a well-known exploit. Ranks up there with SQL-injection.

Though LULZ aside, I don't know that it's such a wise idea to claim credit. It probably would have been difficult for SixApart to claim any monetary damage from The Great Strikethrough, but it's not a stretch to see this thing getting turned over to the FBI. Amazon can claim all those canceled orders as "damage".

Date: 2009-04-13 10:55 pm (UTC)
From: [identity profile] furrbear.livejournal.com
And Cracker "Street-Cred".

Date: 2009-04-13 11:09 pm (UTC)
From: [identity profile] jediknightcub.livejournal.com
Yo. Word to your mother.

Date: 2009-04-14 12:41 am (UTC)
From: [identity profile] joebehrsandiego.livejournal.com
As a non-CS Geek, can I ask what LULZ specifically means?

EX-LJ-friend danlmarmot has it as a CA personalized car tag.

Date: 2009-04-14 12:44 am (UTC)
From: [identity profile] furrbear.livejournal.com
LULZ = plural of LOL
Edited Date: 2009-04-14 12:45 am (UTC)

Date: 2009-04-14 03:51 pm (UTC)
From: [identity profile] hwynym.livejournal.com
As far as I'm concerned, Amazon is still on the hook for all of the perceptions this incident has created.

While this is a plausible explanantion, it's not the explanation they've chosen to give. So, it looks like they targeted GLBT books and then backpedaled when there was an uproar.

If they were hacked, they need to say they were hacked. If they won't come out with a plausible explanation about how a "glitch" would target GLBT titles, then they're not off the hook, as they're choosing a cover-up rather than being open and honest about thing.

Until they do that, I won't buy from them again.
Page generated Mar. 16th, 2026 09:40 am
Powered by Dreamwidth Studios