top | item 4865861

Tumblr hacked?

66 points| depoisfalamos | 13 years ago |tumblr.com | reply

22 comments

order
[+] biot|13 years ago|reply
If you suspect a site has been compromised, wouldn't a better approach be to submit this as a text article explaining your reasons rather than linking to the affected site? Depending on the nature of the hack, the title could easily have been:

  Was Tumblr hacked in order to do drive-by malware installs? (tumblr.com)
Now everyone who clicks is potentially at risk.
[+] 47eo|13 years ago|reply
Indeed, it was kind of stupid from the submitter.
[+] g-garron|13 years ago|reply
Thanks God I click on it while on Linux :)
[+] shortformblog|13 years ago|reply
Keeping an eye on this. The post in question looks like this:

https://dl.dropbox.com/u/58607934/Screen%20Shot%202012-12-03...

It has nailed a number of major accounts, including The Verge, USA Today, Reuters and The Daily Dot.

Buzzfeed has tips on how to keep safe: http://www.buzzfeed.com/ryanhatesthis/hacker-group-exploits-...

Update: The GNAA says that the hack was part of an anti-blogging campaign.

> This was just another part of our "anti-blogging" campaign. GNAA's stance on blogging in general has always been a negative one: in short, blogging is lowering journalistic standards to the point where the number of friends a murderer has on Facebook has become news.

http://www.guardian.co.uk/technology/2012/dec/03/tumblr-cybe...

[+] nbashaw|13 years ago|reply
At the bottom of the spam post it says if you delete the post it will delete your Tumblr account. Since this spreads by people viewing it, it's probably important to point out that deleting the posts will not delete your tumblr account, and you should do it immediately so people viewing your blog don't get infected themselves.
[+] derpenxyne|13 years ago|reply
The exploit uses a "data-uri script tag" in the video embed field. In other words, it runs some sort of script through the section of the site that's supposed to only allow video embed codes from sites like YouTube and Vimeo. A pretty serious security hole.
[+] matthuggins|13 years ago|reply
Mind sharing where you found this info? Did you figure it out yourself?
[+] thezilch|13 years ago|reply
Hacking vector was fixed: https://twitter.com/tumblr

Tumblr engineers have resolved the issue of the viral post attack that affected a few thousand Tumblr blogs. Thanks for your patience.

[+] Hello71|13 years ago|reply
Looking at the other comments, this seems like basic CSRF to me.
[+] j2labs|13 years ago|reply
Nothing particularly interesting seems to have actually happened. Some posts got onto the Dashboard, which was still running. In fact, everything was still working just fine.

Script kiddies found a small crack and went for it.

[+] lysol|13 years ago|reply
It's not really a script kiddie if it's an original exploit, and is still a vulnerability that has cost businesses money.
[+] shortformblog|13 years ago|reply
My entire dashboard was filled with these worm posts an hour ago, and hit a number of major sites.
[+] elcapo|13 years ago|reply
"Script-kiddies" don't author exploits, or discover vulnerabilities.