You are here: silicon.com > Networks > WebWatch

WebWatch

Don't Spread Firefox: Hack attack strikes again

Community site taken offline...

Tags: spread firefox, hacking attack, firefox

By Joris Evers

Published: 5 October 2005 08:45 GMT

Spread Firefox, the marketing website for the open source Firefox web browser, has been hacked again and is expected to be offline until later this month.

The cyber break-in was discovered this week, according to a notice sent on Tuesday by the Spread Firefox team to registered users of the website. The breach was limited to SpreadFirefox.com and did not affect the main Mozilla.org website or Mozilla software, according to the emailed message.

The server that hosts the Spread Firefox website was compromised by attackers who attempted to exploit a security vulnerability in TWiki, according to the notice. TWiki is open source software for the collaborative authoring of online pages called "wikis".

This is the second time the site has been hacked via a flaw in software used to run the website. In July, the marketing site was compromised by attackers who exploited an unpatched security hole in PHP. The Drupal content management system used by the site is written in the PHP scripting language.

After the July attack, Mozilla instituted procedures to ensure it would not overlook any more security fixes. The Spread Firefox team said in its notice: "Unfortunately, those procedures overlooked the installation of the TWiki software, since it is not used by the main Spread Firefox site."

The Firefox marketing website has been taken offline and will be rebuilt from scratch, according to the email. "When the system is rebuilt, all the software will be audited to ensure that security updates will be applied in a timely manner," the team wrote.

The latest attack is not likely to have exposed any user information, according to the email. Still, people should change their password when the site comes back online, the team suggested. Spread Firefox's website should be back online circa 15 October, according to a notice on the site.

The hack is an additional embarrassment to Mozilla, which has emphasised security as a main selling point for its Firefox web browser.

Spread Firefox is the online Firefox marketing hub. Mozilla has successfully used the site to mobilise volunteers to popularise the browser through free marketing techniques such as website buttons and by collecting money for an ad in The New York Times.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
Read and write about internet access at the airports of the world at atlarge.com. Rate airports, and see what others have to say...


  • Jobs
Web Developer within Spread Betting Organisation.

Contract Role: Web Developer within Spread Betting Organisation. The technical requirements are as follows: DHTML, JavaScript, CSS, Cross browser ...

Project Manager (WCM / CMS) - South East

Salary circa GBP65k (flexible) plus excellent benefits. Flexibility to travel due to the client facing activities (circa 20-25%). Project Manager ...

Test Analyst

Ideally you will have the following: 2 years experience testing transactional web sites, Spread betting knowledge some knowledge of EquityFutures ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: