Here is the story of some guy who was doing his daily bloglines thing, when he found a comment that triggered the —always dangerous— question,
what if <!-- insert EVIL ACTION in here -->...
?.
I'm not a hacker, I'm not an expert in system administration nor server management, i don't do password cracking in my spare time, and i don't even speak or write English very well! but i do have common sense, and that is all i need.
Matt Mullenweg, the lead developer of WordPress, is a really smart guy, i even admire him and pretty much all of his work, but i couldn't resist to see
what would happen if I just...
So, here is the story.
After reading one of his comments, it only took me 5 minutes to find out Matt's password, the funny thing is that i tried to convince myself that he wouldn't be that silly, but guess what? he is that silly!.
It is not that i only got access to his blog, he was using the SAME password —really crappy one— for ALL of his information/server/data/etc, I've got access to EVERYTHING MATT, trust me he is hanging from one of his balls right now.
Fortunately for him, as i said before I'm not a hacker, nor a cracker, nor a dirty bastard who did not receive enough love when i was a baby, but imagine what i could have done with that information... just think for a minute.
Here is a lesson for everyone, USE your god damn brain!
I did nothing besides the redirection (yes, you are welcome), and NO i won't be revealing the password until i get confirmation of Matt that it has been changed and everything is
safe.
P.S. I'm sorry Matt, but it was so easy... i couldn't resist.
Ok, now the Matt is back you can have some screenshots.

13 comments:
0dd, both 'photo matt' and his sub-blog matt on the wordpress.com site seem to work normally. What'd you haxxor?
oh nevermind, looks like I may have missed my window of laughiness.
Sorry Charlie, game over.
what was his password, something like opensourceleech or igotrichoffyourwork?
Flamebait if I ever saw it, 8:48pm anonymous...
Are you going to email matt what happened?
he have already emailed me.
Haha, funny, especially since you didn't destroy anything. :)
Now that he's changed it, can you tell us what the password was?
he will be grateful forever dude!
http://photomatt.net/2006/06/07/whoops-2/
you suck! If i were you i would have screwed all of his data, stole his ideas and erase his online world... i repeat today and tomorrow: YOU ARE AN ASSHOLE!
Priceless
It's ok u didnt destroy anything, but i think u should email him first about the problem, and if u want u could write about in ur blog...
Maybe its too easy, but i wouldnt want to see a comment like this on my blog. Hackers should say that they protect us from others, but if noone tried to hacke me, no one would fuck my sites..
Post a Comment