The Watchtower of Destruction: The Ferrett's Journal - interesting...
June 12th, 2004
09:07 am

[Link]

Previous Entry Add to Memories Tell a Friend Next Entry
interesting...
this is very interesting.

(NOTE: Apparently, some fuckwit's been posting an LJ script hack. If you see this in someone's journal, they didn't put it there, and you will be vulnerable if you click it.)

(EDIT: Officials say you don't have to change your password if you've accidentally clicked and had it posted, and that this is "trivial." What this thing does is use your browser's session info, temporarily masquerading as you to post a message in your journal that links back to the hack, all in order to encourage more people to unknowingly spread it. I've written some other thoughts on how this could have been harmful - but this one wasn't, since apparently this particular iteration did nothing aside from posting a message - and, theoretically, could have done nothing but post a message. Your password was not stolen, despite early reports to the contrary. Your user info is safe. And LJ has fixed the security hole, so there should be nothing to worry about for the time being.

(But even so, you know what I really wanted? Spreading LJ viruses and the worry about clicking on the wrong links. Now people can link to even more damaging places!)

Fucking crackers. I hope they all goddamned die.

(Tell me I'm full of it)

Comments
 
Page 1 of 4
<<[1] [2] [3] [4] >>
[User Picture]
From:[info]xforge
Date:June 12th, 2004 01:09 pm (UTC)
(Link)
Frazzen razzen virus script hack...

[User Picture]
From:[info]karlthepagan
Date:June 13th, 2004 03:41 am (UTC)

Re: EVERYONE READ

(Link)
This cannot steal your password. That is false information. Passwords are not stored by LJ in cookies, only a login / session hash is stored.

Furthermore unless you have an entirely ancient and decrepit version of internet explorer or mozilla / netscape this can't even get your session key. I think he probably uses the "blah" image to simply track the spread of his virus.
[User Picture]
From:[info]zarhooie
Date:June 12th, 2004 01:10 pm (UTC)
(Link)
ferrett love, are you sure you meant to do that?
[User Picture]
From:[info]wtfbrain
Date:June 12th, 2004 01:16 pm (UTC)
(Link)
Yeah. Great. Another one. Thanks.
[User Picture]
From:[info]ohhjuliet
Date:June 12th, 2004 01:22 pm (UTC)
(Link)
I've already been sucked in once! It will not happen again!
[User Picture]
From:[info]theferrett
Date:June 12th, 2004 01:48 pm (UTC)
(Link)
Yeah, I caught it from you. I don't blame ya, though. Bah!
[User Picture]
From:[info]erisreg
Date:June 12th, 2004 01:23 pm (UTC)

Re: cute,..

(Link)
/trust
[User Picture]
From:[info]erisreg
Date:June 12th, 2004 01:46 pm (UTC)

Re: cute,..

(Link)
i retract the my ire,in your direction,..o.0
[User Picture]
From:[info]allah_sulu
Date:June 12th, 2004 01:23 pm (UTC)
(Link)
Do you realize that that is probably another password miner, like the Russian "Who has the longest sausage" thing? You should change your password ASAP.
[User Picture]
From:[info]ohhjuliet
Date:June 12th, 2004 01:26 pm (UTC)
(Link)
Why would someone WANT my LJ password?
[User Picture]
From:[info]mirichan
Date:June 12th, 2004 01:34 pm (UTC)
(Link)
Must say I'm not pleased with whoever created that... I already knew to avoid URLS in IRCs... pisses me that now we'll have to start mistrusting links in LJs...

I changed my password and WARNED people in my LJ not to click on such a linked entry...
[User Picture]
From:[info]theferrett
Date:June 12th, 2004 01:47 pm (UTC)
(Link)
Me too. Fucker.
[User Picture]
From:[info]ytaya
Date:June 12th, 2004 01:38 pm (UTC)
(Link)
There was a similar meme doing the rounds, a Russian one, yesterday. I checked it out with LJ support and they said it doesn't represent a security risk. You can check out what they said here.

They're still evil fuckers, mind. They should include a warning that it'll post an entry for you.
[User Picture]
From:[info]wyldkyss
Date:June 12th, 2004 01:43 pm (UTC)
(Link)
Yes, THAT one isn't going to steal your passwords and eat your babies. However! The one that has a username AND password blank.. that one IS evil. Of course, only an idiot would put their password on a meme to start with.
[User Picture]
From:[info]ohhjuliet
Date:June 12th, 2004 01:45 pm (UTC)
(Link)
He posted that in the mac community I belong to, which is how it got to me. He also has the most disturbing icon I've ever seen.
[User Picture]
From:[info]zoethe
Date:June 12th, 2004 01:48 pm (UTC)
(Link)
All I can say is, Jay-sus....
[User Picture]
From:[info]lorriejharris
Date:June 12th, 2004 01:52 pm (UTC)
(Link)
Thanks for the info, Ferrett! I did exactly what you advised, too.
[User Picture]
From:[info]swiftrat
Date:June 12th, 2004 01:53 pm (UTC)

Re: =:{

(Link)
*worries*
[User Picture]
From:[info]gothwalk
Date:June 12th, 2004 01:54 pm (UTC)
(Link)
Dude, it can't get your password. It's using the cookie on your machine. It's trivial; I could write one in about thirty seconds straight. It's no danger, and just a mild annoyance at it posting stuff to your lj that you then have to delete.

It's not a hack. It's not a crack. It's not even up to skript kiddie level, for gods sakes. Stop fussing, man. Chill.
[User Picture]
From:[info]theferrett
Date:June 12th, 2004 01:58 pm (UTC)
(Link)
Still. You know what I really wanted? LJ Viruses. Where I now have to worry about the links I click on.

What a complete and utter fuckwipe. It doesn't have to be Hi-Tech Shit to make something annoying and an asshole.
[User Picture]
From:[info]tormentedartist
Date:June 12th, 2004 02:23 pm (UTC)
(Link)
I hope this piece of shit, dies a slow death !!! And I think some thing that can make a post in your journal is sorta serious !!!! btw
[User Picture]
From:[info]erislover
Date:June 12th, 2004 05:28 pm (UTC)
(Link)
The only way it can make a post in your journal is by using what YOU use to post in your journal. Unless you want post-less journals, not much you can do about it. Sorry.
[User Picture]
From:[info]snowelf
Date:June 12th, 2004 03:23 pm (UTC)
(Link)
Grr...that fuckwit...it makes me so very, very angry that someone would mess with other people like that. I appreciate the warning, Ferret.
(no subject) - (Anonymous) Expand
[User Picture]
From:[info]crumblingredsky
Date:June 12th, 2004 03:25 pm (UTC)
(Link)
Am i the only one here who thought "'Fucking crackers?' He's against annoying white people now?"
[User Picture]
From:[info]temujin9
Date:June 12th, 2004 04:12 pm (UTC)
(Link)
A "cracker" is what everyone thinks about when they hear the word "hacker". Except for actual hackers, which I think Ferrett is, who instead get frustrated at the incorrect usage that American media has caused.
[User Picture]
From:[info]kaymera
Date:June 12th, 2004 03:52 pm (UTC)
(Link)
I'm sorry to bother you but I'm now really thourougly confused and more than a little worried.

"If you see this in someone's journal, they didn't put it there, and you will be vulnerable if you click it."

If I see what in someone's journal? I feel a bit daft now but I really am hugely confused. What should I not click on?
[User Picture]
From:[info]malixe
Date:June 12th, 2004 04:05 pm (UTC)
(Link)
It's the this is interesting link itself that you don't want to click on.

I bit on it in a friend's journal. My initial reaction was more along the lines of 'great--this is one of those practical joke things that gets played on you and then you turn around and play on the next sucker to come along...'....

Now after reading these responses I'm becoming a bit more concerned...
[User Picture]
From:[info]wolfieboy
Date:June 12th, 2004 04:09 pm (UTC)

Re: Not real interesting

(Link)
Note that if you go to this persons userinfo page, you'll see that he lists a toll free number for you to call and express your opinion. I even verified that it's the same as the toll free number on his domain record so he's not trying to get someone else's number implicated.

You might also want to direct people to this FAQ that tells them how to expire all sessions which they will likely want to do. This won't take your password (since your password isn't stored in the cookie) but it could do all sorts of interesting things with your journal if it keeps the session id.

If possible, folks also want to choose "Bind to IP Address" when they login as mentioned in this FAQ. This means that if someone manages to keep the session id, they can't use it unless they can spoof your ip address.

Note that I've looked at the code for the current mischief and it doesn't do more than is apparent but that doesn't mean that others won't.
From:[info]flense
Date:June 12th, 2004 04:12 pm (UTC)

Re: Not real interesting

(Link)
binding is a great idea - unless you have a dynamic ip (right?)
[User Picture]
From:[info]sneakingyoda
Date:June 12th, 2004 04:35 pm (UTC)

Re: Forgive me on not understanding this one.

(Link)
OK Ferret,

Now is the link you have up on YOUR entry the real deal? or something you simply fabricated to look like the real deal so that your readers will not be infected even if they do bite?
[User Picture]
From:[info]quizzicalsphinx
Date:June 12th, 2004 04:55 pm (UTC)

Re: Forgive me on not understanding this one.

(Link)
The link on this page links back to one of the Ferret's own entries. No worries; the bomb--here at least--has been defused.
[User Picture]
From:[info]redpandacub
Date:June 12th, 2004 05:02 pm (UTC)
(Link)
It's not a permanent cure... and the fucktards crackers still go on breathing - but this will save everyone A LOT of undue heartache

TURN OFF JAVASCRIPT!!!

That's how the virus is running - and it's that simple to avoid

this should also be a natural precaution to anyone surfing on any public site - fine, so you won't get to see those cute little roll-overs or super happy fun pop-up windows... but you'll still have your LJ account.

I hope this can be of some help to y'all
[User Picture]
From:[info]jenlight
Date:June 12th, 2004 07:50 pm (UTC)
(Link)
It isn't a virus. It's harmless. No database is made. The passwords aren't being harvested.

[User Picture]
From:[info]draconity
Date:June 12th, 2004 07:32 pm (UTC)
(Link)
I have a friend who downloaded the code and studied it. He says it's harmless.
[User Picture]
From:[info]lillybilly
Date:June 12th, 2004 07:32 pm (UTC)
(Link)
what if you're not able to change your password again?
[User Picture]
From:[info]brackish18
Date:June 12th, 2004 08:03 pm (UTC)
(Link)
i cant change my password?
From:[info]xlucidiquex
Date:June 12th, 2004 09:33 pm (UTC)
(Link)
NEITHER CAN I..

uh oh.
From:[info]youcallhersusie
Date:June 12th, 2004 08:06 pm (UTC)
(Link)
It's impossible for it to steal your password as explained by my boyfriend.

http://www.livejournal.com/users/coolashell/364234.html?mode=reply
The Ferrett's Domain Powered by LiveJournal.com