[x]Blackmoor Vituperative

Monday, 2006-06-05

Circuit City forum hacked

Filed under: Security — bblackmoor @ 18:03

I currently work at Circuit City as a programmer/analyst. From time to time I make suggestions intended to bring my department into compliance with widely-known best practices concerning security, server administration, the development process, and so forth. Thus far, not a single one of these suggestions has been recognized as addressing a valid concern, much less implemented.

So it was with some interest that I read that Circuit City’s online forum was hacked to infect users with spam bots. To be fair to Circuit City, in this instance I do not believe they were any more irresponsible than most companies who run web sites — including my own. The patch for their forum software was released on 2006-05-17. Their forum was hacked on 2006-05-30. That’s less than two weeks.

Of greater concern to me is that the people who are the real victims of this hack, the visitors to Circuit City’s web site, would only have been affected if they were stupidly, inexplicably still using Internet Explorer as their web browser. What the hell is wrong with you people? For crying out loud, switch to Firefox already!