<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-29412006</id><updated>2009-10-02T18:52:53.549-07:00</updated><title type='text'>Matt Mullenweg</title><subtitle type='html'>The Story of a Hack and a Matt.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://hackmatt.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29412006/posts/default'/><link rel='alternate' type='text/html' href='http://hackmatt.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Kovarde, Inc</name><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-29412006.post-116550865442948941</id><published>2006-12-07T08:16:00.000-08:00</published><updated>2006-12-07T08:24:14.430-08:00</updated><title type='text'>Eat Your Own Dog Food</title><content type='html'>Well it seems like the guy who actually got into Matt´s account was not that clever after all, he forgot to secure his own email address, so here I'm!

It was really stupid to get access to his email address, he used &lt;strong&gt;automattic&lt;/strong&gt; as the password, so it took me no more than five minutes to hack him back.

Ok, so what can we do with this blog right now? Oh yes, i do have some mailing between the guy and Matt, and i do have his password... if you want some insides drop some money on the left and i see what i can do ;)

Oh, BTW, anyone interested in buying this blog or should i wait for a Google call?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29412006-116550865442948941?l=hackmatt.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackmatt.blogspot.com/feeds/116550865442948941/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29412006&amp;postID=116550865442948941' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29412006/posts/default/116550865442948941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29412006/posts/default/116550865442948941'/><link rel='alternate' type='text/html' href='http://hackmatt.blogspot.com/2006/12/eat-your-own-dog-food.html' title='Eat Your Own Dog Food'/><author><name>Kovarde, Inc</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='05062433707872280058'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29412006.post-116317493829690285</id><published>2006-11-10T08:06:00.000-08:00</published><updated>2006-11-10T08:32:19.246-08:00</updated><title type='text'>ReviewThem</title><content type='html'>First of all i want to say that they are paying me some money to tell you this, in fact i have to say that this is a sponsored post because those are the rules of this game, but i can still say whatever i want about this new service.

&lt;a href="http://www.reviewme.com"&gt;RevieMe&lt;/a&gt; is yet another service that has launched today that enables bloggers to write sponsored posts in return for a payment from advertisers. 

Whether you are using the pretty &lt;a href="http://hackmatt.blogspot.com/2006/06/hack-matt.html"&gt;unsecured blogging platform that we all love&lt;/a&gt; or the old fashioned blogger, you can make some money with RevieMe just for... well, blogging.

It was easy schmeazy to sign up, and within a few seconds I had an account and my first review was waiting on the dashboard. 

&lt;blockquote&gt;Bloggers: Get paid to review services and Web sites that are of interest to your readers, and reap the benefits of conversation with advertisers.

Advertisers: Get your service or Web site reviewed by bloggers, gaining your site traffic, invaluable feedback, and word of mouth buzz.&lt;/blockquote&gt;

Do you blog? Go on and &lt;a href="http://www.reviewme.com"&gt;sign up&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29412006-116317493829690285?l=hackmatt.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackmatt.blogspot.com/feeds/116317493829690285/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29412006&amp;postID=116317493829690285' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29412006/posts/default/116317493829690285'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29412006/posts/default/116317493829690285'/><link rel='alternate' type='text/html' href='http://hackmatt.blogspot.com/2006/11/reviewthem.html' title='ReviewThem'/><author><name>Kovarde, Inc</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='05062433707872280058'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29412006.post-114978683254892323</id><published>2006-06-08T09:48:00.000-07:00</published><updated>2006-06-08T10:45:45.550-07:00</updated><title type='text'>The Comment</title><content type='html'>Well, now that i see all the sites i got access to has been reconfigured, i will let you know which is the comment that gave me the password.

But first, i want to cite this:
&lt;blockquote&gt;Wow. What a big brain this guy has. Not only did he guess an easily guessed password based on published clues, but he -- a non hacker -- figured out what to do with that knowledge to make an ass of himself! &lt;a href="http://www.threadwatch.org/node/6861"&gt;#&lt;/a&gt;&lt;/blockquote&gt;This was only to probe that no one is safe from hackers, not even smart people as Matt —not you, obviously— and even more important is that you have to take good care of your information and what you give public access in the web.

This may not be the best way to do it, but it gets to the point, so if i make the difference, even for 1 person, then it would have worked.

Don´t like it, close the window, It is called freedom.

Now, back to the comment thing... forget all the stupid ideas about security risks, password cracking, md5 hashes , exploits and all that crap, OK? It has nothing to do with WordPress. Wordpress is perfectly safe, and you can keep on using it.

I got the password in plain text, and i found it in a public web address, that was accessible to ANYONE who has an internet connection.

The comment is here &lt;a href="http://asymptomatic.net/2006/06/01/2369/dear-web-development-community/#comment-62017"&gt;http://asymptomatic.net/2006/06/01/2369/dear-web-development-community/#comment-62017&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29412006-114978683254892323?l=hackmatt.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackmatt.blogspot.com/feeds/114978683254892323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29412006&amp;postID=114978683254892323' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29412006/posts/default/114978683254892323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29412006/posts/default/114978683254892323'/><link rel='alternate' type='text/html' href='http://hackmatt.blogspot.com/2006/06/comment.html' title='The Comment'/><author><name>tenrules</name><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29412006.post-114973320965916768</id><published>2006-06-07T19:06:00.000-07:00</published><updated>2006-06-07T20:58:59.966-07:00</updated><title type='text'>Hack the Matt</title><content type='html'>Here is the story of some guy who was doing his daily bloglines thing, when he found a comment that triggered the —always dangerous— question, &lt;strong&gt;what if&lt;/strong&gt; &amp;lt;!-- insert EVIL ACTION in here --&amp;gt;... &lt;strong&gt;?&lt;/strong&gt;.

I'm not a hacker, I'm not an expert in system administration nor server management, i don't do password cracking in my spare time, and i don't even speak or write English very well! but i do have common sense, and that is all i need.

&lt;a href="http://hackmatt.blogspot.com/"&gt;Matt Mullenweg&lt;/a&gt;, the lead developer of WordPress, is a really smart guy, i even admire him and pretty much all of his work, but i couldn't resist to see &lt;strong&gt;what would happen if I just...&lt;/strong&gt;

So, here is the story.

After reading one of his comments, it only took me 5 minutes to find out Matt's password, the funny thing is that i tried to convince myself that he wouldn't be that silly, but guess what? he is that silly!.

It is not that i only got access to his blog, he was using the SAME password —really crappy one— for ALL of his information/server/data/etc, I've got access to EVERYTHING MATT, trust me he is hanging from one of his balls right now.

Fortunately for him, as i said before I'm not a hacker, nor a cracker, nor a dirty bastard who did not receive enough love when i was a baby, but imagine what i could have done with that information... just think for a minute.

Here is a lesson for everyone, USE your god damn brain!

I did nothing besides the redirection (yes, you are welcome), and NO i won't be revealing the password until i get confirmation of Matt that it has been changed and everything is &lt;em&gt;safe&lt;/em&gt;.

&lt;abbr title="NOT Princess Sophie"&gt;P.S.&lt;/abbr&gt; I'm sorry Matt, but it was so easy... i couldn't resist.


Ok, now the Matt is back you can have some screenshots.

&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/701/2482/1600/1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/blogger/701/2482/320/1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/701/2482/1600/2.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/blogger/701/2482/320/2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29412006-114973320965916768?l=hackmatt.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackmatt.blogspot.com/feeds/114973320965916768/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29412006&amp;postID=114973320965916768' title='13 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29412006/posts/default/114973320965916768'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29412006/posts/default/114973320965916768'/><link rel='alternate' type='text/html' href='http://hackmatt.blogspot.com/2006/06/hack-matt.html' title='Hack the Matt'/><author><name>tenrules</name><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>13</thr:total></entry></feed>