+ Reply to Thread
Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 23

Thread: Flippa Got Hacked. Your Account Got Compromised. Days Ago. Got the notification?

  1. #11
    Administrator
    Join Date
    Jan 2010
    Location
    Essex, UK
    Posts
    5,768
    Blog Entries
    26
    Thanks
    1,751
    Thanked 987 Times in 591 Posts
    Rep Power
    10
    Quote Originally Posted by hooperman View Post
    I'm surprised that nobody has raised the issue on the SP forum.
    Damn. OK, I've posted it now as I've just realised, it's a common login for Flippa and Sitepoint.

    I don't have to go through my Sitepoint PMs as well now, do I? Arggh!!

  2. #12
    Moderator
    Join Date
    Jan 2010
    Location
    Canada
    Posts
    983
    Thanks
    71
    Thanked 268 Times in 163 Posts
    Rep Power
    24
    I wonder if the hack was as simple as just changing the user id in the url? I tried it this morning and it didn't work but who knows.

    I've seen other systems (million+ plus) that left this hole in their security, it wouldn't surprise me if Flippa did as well (especially based on their lack of quality control in general over code).

  3. #13
    Administrator
    Join Date
    Jan 2010
    Location
    Essex, UK
    Posts
    5,768
    Blog Entries
    26
    Thanks
    1,751
    Thanked 987 Times in 591 Posts
    Rep Power
    10
    Video now released.

    Flippa makes a blog post about the breach.

  4. #14
    Moderator
    Join Date
    Jan 2010
    Location
    Canada
    Posts
    983
    Thanks
    71
    Thanked 268 Times in 163 Posts
    Rep Power
    24
    Pretty close to what I thought, except the url was in the forgot password link, not the overall url.

  5. #15
    Top Contributor
    Join Date
    Jan 2010
    Location
    Manchester, UK
    Posts
    1,365
    Thanks
    184
    Thanked 94 Times in 76 Posts
    Rep Power
    24
    Interesting that Flippa don't acknowledge the risk associated with the ability for hackers to log in as any user they wish. In that blog post they've listed all the "low risk" admin functions that hackers had access to, but have ommitted the function that gives them the ability to log in as any Flippa user. No point worrying people with the truth. Most people won't care that hackers were able to credit their accounts, but they might care if they realised that their PMs and other private info were accessible.

  6. #16
    Administrator
    Join Date
    Jan 2010
    Location
    Essex, UK
    Posts
    5,768
    Blog Entries
    26
    Thanks
    1,751
    Thanked 987 Times in 591 Posts
    Rep Power
    10
    I don't think most users care whether Flippa reads their PMs. We're talking about the average player being the type who gets excited about making $30 selling his template.

    People who have more at stake, professionals accustomed to respect, people used to handling confidential information, business managers etc., aren't the average Flippa users. Those who occasionally sign up to sell a quality site aren't ever going to know that Flippa is ... a bit different

  7. #17
    Senior Member
    Join Date
    Apr 2010
    Location
    UK
    Posts
    416
    Blog Entries
    8
    Thanks
    79
    Thanked 128 Times in 77 Posts
    Rep Power
    16
    Quote Originally Posted by Clinton View Post
    I don't think most users care whether Flippa reads their PMs. We're talking about the average player being the type who gets excited about making $30 selling his template.

    People who have more at stake, professionals accustomed to respect, people used to handling confidential information, business managers etc., aren't the average Flippa users. Those who occasionally sign up to sell a quality site aren't ever going to know that Flippa is ... a bit different
    I suspect all of this will be largely ignored by the majority of users and Flippa have no reason to make a bigger deal of it. Where it may get messy is if it does actually come to light that someone has had their confidential information stolen/misused as a result of this hack. Unlikely seeing as the hacker is "ethical" but what's to say it hasn't already been done and not disclosed?

    In my opinion, the list has the most value - I don't really know anything about hacking or the market for this kind of stuff, but I'd imagine it would be worth a fair chunk of change to the right buyer.

  8. #18
    Moderator
    Join Date
    Jan 2010
    Location
    U.S.A.
    Posts
    1,570
    Thanks
    53
    Thanked 226 Times in 162 Posts
    Rep Power
    30
    Quote Originally Posted by hooperman View Post
    Interesting that Flippa don't acknowledge the risk associated with the ability for hackers to log in as any user they wish. In that blog post they've listed all the "low risk" admin functions that hackers had access to, but have ommitted the function that gives them the ability to log in as any Flippa user. No point worrying people with the truth. Most people won't care that hackers were able to credit their accounts, but they might care if they realised that their PMs and other private info were accessible.
    That would also involve making it clear that the Flippa admins can read everyone's PMs, which is probably not something that they would like to start a discussion about.

    I think they did an OK job of handling this problem, since they patched the hole quickly, put out an explanation relatively quickly, and made some smart decisions not to store passwords in plaintext or store any credit card information with the accounts.

  9. #19
    Moderator
    Join Date
    Jan 2010
    Location
    U.S.A.
    Posts
    1,570
    Thanks
    53
    Thanked 226 Times in 162 Posts
    Rep Power
    30
    I see that you two are over at the Flippa blog stirring up trouble.

    I went there to make the points that you did, but you already beat me to it. Dave's attempt to blow off the first comment isn't surprising, and I wonder what the reaction will be if the questions continue.

  10. #20
    Administrator
    Join Date
    Jan 2010
    Location
    Essex, UK
    Posts
    5,768
    Blog Entries
    26
    Thanks
    1,751
    Thanked 987 Times in 591 Posts
    Rep Power
    10
    I wonder what the reaction will be if the questions continue.
    They won't.
    a) Regular Flippa fanboys aren't bothered
    b) Flippa has a delete button

+ Reply to Thread

Similar Threads

  1. I've been hacked.
    By Andy in forum General & Miscellaneous
    Replies: 7
    Last Post: May 28th, 2010, 04:05 PM
  2. Transferring a Clickbank account when selling a website
    By Clinton in forum Selling A Website, Blog or Domain
    Replies: 2
    Last Post: May 18th, 2010, 05:50 PM
  3. Anyone got an account with text-link-ads.com? I have a question
    By 3Six in forum General & Miscellaneous
    Replies: 6
    Last Post: February 6th, 2010, 11:47 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts