Posted by Dr. Bob on May 16, 2007, at 12:22:35
In reply to Re: change your password, posted by Dr. Bob on May 15, 2007, at 11:58:42
> > I'm still working on fixing things
FYI, what the hacker did was insert malicious instructions into a post that sent them information from the Babble cookies of those who came across that post. You can see for yourself what that included:
http://www.dr-bob.org/cgi-bin/pb/extras.pl#cookies
As far as I know, they didn't get access to the server. Or, as I mentioned before, to the computers of any users. Those who had cookies (or Javascript) turned off weren't affected -- and are probably safer in general.
I've updated the posting software to prevent that from happening again, and I'll turn it back on after people have had some time to change their passwords.
The issue with the Babblechat software was that it wasn't checking the current Babble password, but that should be fixed now, too.
Thanks to those who've sent notes of support, I've really appreciated them. :-)
Bob
poster:Dr. Bob
thread:758315
URL: http://www.dr-bob.org/babble/admin/20070423/msgs/758338.html