Hello,
An unauthorized person gained administrative access to typo3.org backend due to a weak password of one of the backend users. The backend was NOT hacked as I wrote before.
All accounts are currently locked. Because of the single sign on solution, this also affects forge and bugs and some other domains. It's highly recommend to change all your passwords that might be similar to the password you used as your typo3.org account. To make it clear! This affects ALL frontend user accounts. Not only the backend users!
It's a really bad situation and even if the passwords where stored a md5 hashes. If you have very simple passwords (a single word for example) it is possible to get your password from a dictionary for example! So once again:
CHANGE YOUR PASSWORDS IF THEY ARE SIMILAR TO THE TYPO3.ORG FE ACCOUNT!
Greets,
Thomas
| M | T | W | T | F | S | S |
|---|---|---|---|---|---|---|
| « Oct | Jan » | |||||
| 1 | 2 | |||||
| 3 | 4 | 5 | 6 | 7 | 8 | 9 |
| 10 | 11 | 12 | 13 | 14 | 15 | 16 |
| 17 | 18 | 19 | 20 | 21 | 22 | 23 |
| 24 | 25 | 26 | 27 | 28 | 29 | 30 |
Do you have some problems with your server or is it because of maintainance?
I hope, my answers will help you for your statistics. Nice to meet you 2010!
Hi Peter, that is already fixed. :-) Greets, Thomas
Hey, great & thanks. Hint: It should be T3DD10 in question 33, not T3DD09 ;-). Cheers, Peter
I just updated the blog entry with the checkout command, see bottom of the page I posted in the last...
#1: Juergen Egeling commented on Saturday, 15-11-08 17:38
Hi,
as far as we investigated, typo3.org was not hacked, but one password was exposed, and a person not allowed to use the backend was using a backend login. I recommend reading http://en.wikipedia.org/wiki/Social_engineering_(computer_security) and http://en.wikipedia.org/wiki/Password_policy (do not have the same pasword on two websites.)
best
Juergen