Posted by d3bruts1d on October 4, 2005 at 3:07 pm

The famous Firefox promotion site, SpreadFireFox.com was taken down by hackers. Here is the email sent out to all members of SpreadFirefox.com:

The Spread Firefox Team became aware this week that the server hosting Spread Firefox, our community marketing site, has been accessed by unknown remote attackers who attempted to exploit a security vulnerability in TWiki software installed on the server. The TWiki software was disabled as soon as we were aware of the attempts to access SpreadFirefox.com. This exploit was limited to SpreadFirefox.com and did not affect mozilla.org web sites or Mozilla software.

We have scanned Spread Firefox servers and at this time do not believe any sensitive data was taken, but as a precautionary measure we have shutdown the site and will be rebuilding the web site from scratch. We also recommend that you change your Spread Firefox password and the password of any accounts where you use the same password as your SpreadFirefox account. We will notify you again when the site is back up with instructions on how to change your password. (Note: We do use MD5 hashing on the passwords, but MD5 cannot protect all passwords against off-line dictionary style attacks.)

After Spread Firefox was compromised in July, we instituted procedures to ensure that we apply all security fixes to the software running the site (Drupal and PHP) as soon as they become available. Unfortunately, those procedures overlooked the installation of the TWiki software since it is not used by the main Spread Firefox site. When the system is rebuilt, all the software will be audited to ensure that security updates will be applied in a timely manner. We deeply regret this incident and any inconvenience this may have caused you.

Sincerely,
Spread Firefox Team
Mozilla Foundation

Things don’t look good for the Firefox Fanboi’s that run the site, as this was the 2nd time the site has been downed by those pesky hackers.

Tech | Permalink

 

Trackbacks

(Trackback URL)

close Reblog this comment
blog comments powered by Disqus


About d3bruts1d.com
d3bruts1d.com is my [d3bruts1d] collection of news, rants, and random thoughts relating to the subjects Technology, Gaming, Entertainment, and just about everything else. This place is in no way meant to be considered a serious or professional news blog, in fact anyone who attempts to take it as such should probably seek professional psychiatric help immediately. It's here so that I can share with other people the things that interest me. If you're here, then hopefully you share similar interest. If we have nothing in common, then I have but one question for you, "why on God's green Earth are you here?" If you happen to be as messed up as I am, feel follow me on Plurk, FriendFeed, or any of other of the many social networks and websites I'm on.
d3bruts1d.com © 2001-2009. All Rights Reserved.