Location: Feedback

Discussion: Don't make me start another protest.Reported This is a featured thread

Showing 4 posts
Marsden
Marsden
Don't make me start another protest.
May 10 2011, 6:47 PM EDT | Post edited: May 10 2011, 6:47 PM EDT
At 8:54am GMT an account called, "wetpaint" which was unbanable uploaded 3 files to the ZSDW which were viruses.

The virus in question was Alureon.

At the same time the homepage had a 0x0 pixel youtube embeded with no edit history of who did it.

It took us close to an hour to repair everything.

Has Wetpaint been compromised? And if so what other wiki format sites would you suggest I bring the ZSDW to as a replacement?
Do you find this valuable?    
Naru2008
Naru2008
1. RE: Don't make me start another protest.
May 10 2011, 7:17 PM EDT | Post edited: May 10 2011, 7:17 PM EDT
Hey Marsden. (:

I shot Jeremy a message about the Wetpaint account posting viruses on the site. He should look into it and reply shortly. I doubt there is any way the Wetpaint account was hacked. I'm sure Wetpaint uses secure passwords. The staff member on the account might have not known it was a virus and it looked safe. What kind of "files" did they upload?
Do you find this valuable?    

Mod_Kaeleigh
2. RE: Don't make me start another protest.
May 10 2011, 9:00 PM EDT | Post edited: May 10 2011, 9:00 PM EDT
"At 8:54am GMT an account called, "wetpaint" which was unbanable uploaded 3 files to the ZSDW which were viruses.

The virus in question was Alureon.

At the same time the homepage had a 0x0 pixel youtube embeded with no edit history of who did it.

It took us close to an hour to repair everything.

Has Wetpaint been compromised? And if so what other wiki format sites would you suggest I bring the ZSDW to as a replacement?"
Since you've deleted the attachments containing viruses, there isn't a way to trace the original uploader. Jeremy should be able to figure it out through some more advanced checking, but it'll have to wait until tomorrow. The password and email address of the account is the same; it was not compromised. Besides, if a hacker had actually taken over the staff account, they would surely have abused their power in far worse ways. If the uploader was, in fact, the Wetpaint account, then it was probably a staff member doing testing.
Do you find this valuable?    
jeremy_wetpaint
jeremy_wetpaint
3. RE: Don't make me start another protest.
May 12 2011, 1:32 PM EDT | Post edited: May 12 2011, 1:32 PM EDT
We can find no record of this happening, but just to be on the safe side we are changing the password on the Wetpaint account. If anyone sees something fishy like this is the future, I would recommend taking screen shots. Do you find this valuable?    

Related Content

  (what's this?Related ContentThanks to keyword tags, links to related pages and threads are added to the bottom of your pages. Up to 15 links are shown, determined by matching tags and by how recently the content was updated; keeping the most current at the top. Share your feedback on Wetpaint Central.)