(Untitled)

Jun 13, 2004 13:40

DO NOT CLICK ON THE 'THIS IS INTERESTING' or 'WHOS SAUSAGE IS LONGEST' LINKS YOU MAY SEE IN YOUR FRIENDS LIST. IT IS A LJ HACK THAT WILL STEAL YOUR LJ PASSWORD AND POSSIBLY LOCK YOU OUT OF LJ (BY CHANGING YOUR LJ PASSWORD). IT IS ALONG THE SAME LINES AS THE RUSSIAN 'NAME' MEME THAT WENT AROUND YESTERDAY ( Read more... )

Leave a comment

Comments 2

Re: straight from lj support... lokiofasgard June 13 2004, 11:44:05 UTC
"[...]Once again:

1). There was no security risk to these memes. They did not have your password. They could not get your password. The only thing that they could do was cause an entry to be posted to your journal, by telling LJ "hey, post an entry with this content, using the username and password that's in the login cookie". It could not read the login cookie, nor could it save the cookie elsewhere. It did not work if you were not logged into LJ at the time.

2). It's academic, because it's been fixed, and the fix is live.

EDIT: [...]No, they are not security risks, and yes, they are being patched. There is no risk of data loss, and no risk of losing control of your journal."

Reply


pyroman87 June 13 2004, 20:27:16 UTC
true, if you stop it on the page it redirects you to (before the second redirect to your update lj screen) and you look at the source code, nowhere does it say password or anything that looks like it could steal your shit.

Reply


Leave a comment

Up