theljstaff ([info]theljstaff) wrote in [info]news,
@ 2009-09-23 05:17:00
Previous Entry  Add to memories!  Tell a Friend  Next Entry
Media embedding change - important notice
As you may have already noticed, some video and media embedding in LiveJournal entries have been disabled, and content and security level of some entries may have changed unexpectedly. Both are related to a web security exploit that affected some entries on LiveJournal for approximately two hours today. Here is what you should know:
  • You should check your recent entries to be sure the security level has not been changed and embed tags (as described below) have not been added.
  • This exploit was spread through malicious Flash code embedded in journal entries.
  • To combat the exploit, most video and other media embedding has been disabled - we will re-enable them on a site-by-site basis over the coming hours and days.
  • Once media embedding was disabled, the exploit was stopped; it is no longer a risk.
  • If you see four boxes (picture below) on a friend's entry, you should inform your friend since they may not be aware of what occurred.

What occurred today caused a limited but serious privacy breach, so we are making this post in order to inform you of the issue, what actions this exploit performed, and how to know if you have been affected. All of the information provided here is offered to the best of our knowledge right now, and if it substantially changes we will update this post or take other action to notify you.

We received several reports beginning at about 7:45 p.m. PDT on Tuesday, September 22nd (2:45 a.m. GMT Wednesday, September 23rd) that entries had been mysteriously altered - by adding additional code and/or by altering the security level. When the users attempted to return the entries to their previous state (taking out the added content or returning the security level to the chosen one), their changes were often reversed again.

Developers were promptly notified, and upon investigation it was determined that the exploit took place through a cross-domain scripting in an embedded Flash file. All media embedding was disabled immediately. At the present time, media embedding from YouTube and RuTube is re-enabled, but we will be adding to that list over the coming days.

How the exploit was spread:
- Viewing an entry with the infected media caused the script to modify the latest entry of the account which viewed it, and added the malicious code to that entry.

What this exploit did:
- When a user who was logged in viewed an infected post, the flash would then make a cross-domain request to livejournal.com
- The most recent post was then edited to add the flash files, and all settings were changed back to default (default userpic, no mood listed, and the security setting was changed to journal default, for example)
- The file then recorded the email address listed on the "Edit Profile" page - meaning, it recorded the email address regardless of the privacy settings
- While the exploit was active (at this time we believe it was about 1-2 hours), affected posts that were edited by the journal owners to their original state would be reverted back to the infected state (not able to be edited/changed)

What this exploit *did not* do:
- It did not steal any passwords, manipulate or "steal" login cookies, or record any information other than an email address
- It was rendered inactive at 8:50 p.m. PDT (September 22nd)/3:50 a.m. GMT/UTC (September 23rd), when LiveJournal engineers disabled embedded media (such as video files) to stop it from spreading
- It did not infect a computer or harm it in any way

How to identify an affected entry/account:
- Accounts which have been affected will have a recent entry with these four boxes at the bottom:
picture of four disabled media containers
- This will be one of the most recent entries on the journal and/or the top entry (if it is a backdated top-post)
- If no entry with this modification is present, the account has not been affected.

After investigation of the JavaScript code that was found, we believe there are two privacy breaches potentially affecting these journals:
- One or more of the most recent entries in the journal may have had their privacy settings removed; therefore a post set to friends-only or private may have been made public, if the journal default entry-security level is set to "public"
- The email address (whether hidden or not) associated with the account may have been sent back to a server controlled by the attacker

The scope of the exploit/number of users affected:
- We believe this was present for more than one hour but less than two
- Through reports and our investigation this evening, we've seen fewer than 100 affected entries; however, due to the nature of friends pages it is likely more widespread than this
- At this time, we believe the number of users affected is limited - we will investigate activity logs and other data in order to determine with more accuracy the scope of this issue



Page 1 of 10
<<[1] [2] [3] [4] [5] [6] [7] [8] [9] [10] >>

(442 comments) - (Post a new comment)


[info]rinygrin
2009-09-23 12:23 pm UTC (link)
Yikes, thanks for getting on top of this security kerfuffle.

(Reply to this) (Thread)


[info]zephret
2009-09-26 10:50 pm UTC (link)

(Reply to this) (Parent)


[info]fightingoutside
2009-09-23 12:25 pm UTC (link)
Wow. D= Thanks for taking care of it.

(Reply to this) (Thread)


[info]litch
2009-09-24 01:52 am UTC (link)
disabling embedded media isn't really "taking care of it"

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]dimfuture, 2009-09-24 05:35 am UTC (Expand)
(no subject) - [info]acpizza, 2009-09-25 07:50 pm UTC (Expand)
(no subject) - [info]funtarded, 2009-09-25 10:54 pm UTC (Expand)

[info]lalita82
2009-09-23 12:29 pm UTC (link)
Scary, thanks for solving the problem and letting us know.

(Reply to this)


[info]tsukinofaerii
2009-09-23 12:32 pm UTC (link)
Thank you for letting us know! ♥

(Reply to this)


[info]chipleduff
2009-09-23 12:34 pm UTC (link)
Thanks LJ for bringing your A game to this.

(Reply to this)


[info]kazamesu
2009-09-23 12:34 pm UTC (link)
What a pickle; thanks for taking care of it so quickly.

(Reply to this)


[info]mosinging1986
2009-09-23 12:35 pm UTC (link)
Thank you for taking care of this.

(Reply to this)


[info]baggers
2009-09-23 12:36 pm UTC (link)
Thanks for getting onto this so quickly. Though I doubt it was 100 users, since I got hit and I know of two others.

(Reply to this) (Thread)(Expand)


[info]rhiannon_666
2009-09-23 12:38 pm UTC (link)
I wasn't affected and I don't know any one who was.

The point was that when you viewed an infected post, your journal similarly was, so therefore it makes sense that you knew a few people who did.

Just sayin'

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]baggers, 2009-09-23 12:49 pm UTC (Expand)
(no subject) - [info]3771, 2009-09-23 12:51 pm UTC (Expand)
(no subject) - [info]allyphoe, 2009-09-23 01:48 pm UTC (Expand)
(no subject) - [info]janinedog, 2009-09-23 03:01 pm UTC (Expand)
(no subject) - [info]jmthane, 2009-09-23 04:10 pm UTC (Expand)
(no subject) - [info]mellymell, 2009-09-24 12:44 am UTC (Expand)
(no subject) - [info]lauramcewan, 2009-09-23 01:58 pm UTC (Expand)
(no subject) - [info]tifarette, 2009-09-23 02:54 pm UTC (Expand)
(no subject) - [info]smarriveurr, 2009-09-23 03:52 pm UTC (Expand)
(no subject) - [info]maidenjedi, 2009-09-23 04:03 pm UTC (Expand)
(no subject) - [info]ajjones, 2009-09-23 04:27 pm UTC (Expand)
(no subject) - [info]griffen, 2009-09-23 06:24 pm UTC (Expand)
(no subject) - [info]siege, 2009-09-24 03:08 am UTC (Expand)
(no subject) - [info]electrocoustic, 2009-09-26 10:12 am UTC (Expand)
(no subject) - [info]iswari, 2009-09-28 07:20 pm UTC (Expand)

[info]melinchains
2009-09-23 12:37 pm UTC (link)
Ah thanks LJ, just spotted those boxes on a friend's page. I'll go let him know. :)

(Reply to this) (Thread)


[info]ladykalessia
2009-09-23 05:24 pm UTC (link)
Check your own as well! I caught it from a friend - was going "Hmm, her handwork images aren't loading, sad!" and then woke up to this. :\

(Reply to this) (Parent)


[info]qfemale
2009-09-23 12:37 pm UTC (link)
Thank you for this information.

(Reply to this)


[info]danceinacircle
2009-09-23 12:39 pm UTC (link)
I know how late you guys were up diagnosing and fixing this, and I just want to give you all hugs and coffee. <33333333333333 You rock.

(Reply to this)


[info]norabombay
2009-09-23 12:40 pm UTC (link)
Damnit. They got me.

(Reply to this) (Thread)


[info]solarbird
2009-09-23 02:56 pm UTC (link)
Yeah, me too, overnight - sometime before 5:44am PDT today, based on comments.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]drglam, 2009-09-23 10:49 pm UTC (Expand)

[info]arithmetica
2009-09-23 12:42 pm UTC (link)
Now that explains why my post wasn't working last night. Good to know LJ was on the exploit quick!

(Reply to this)


[info]prokhozhyj
2009-09-23 12:42 pm UTC (link)
Thanks for information and for your work.

(Reply to this)


[info]dewdropinn
2009-09-23 12:42 pm UTC (link)
Thanks again, LJ. Excellent job ♥

(Reply to this)


[info]countlibras
2009-09-23 12:46 pm UTC (link)
I got hit. I never even noticed there was a problem.

(Reply to this)


[info]bonniers
2009-09-23 12:46 pm UTC (link)
Thanks for taking care of this so promptly. Nice work!

(Reply to this)


[info]enekoro_sama
2009-09-23 12:47 pm UTC (link)
Much thanks for the warning. I haven't been affected (as far as I know...), but it's still scary. D:

(Reply to this)


[info]dominitus
2009-09-23 12:48 pm UTC (link)
Sounds like you guys did some good work over there recently! Cheers, well done, keep it up. :)

(Reply to this)


[info]stephbg
2009-09-23 12:49 pm UTC (link)
FYI My account was affected as described. Details on request.

(Reply to this)


[info]franzi1981
2009-09-23 12:49 pm UTC (link)
First of all, thanks for the fast response!

I do have a question, though - are there any plans to protect LiveJournal from future Cross-Domain-Scripting attacks, other than whitelisting embedded content? After all, malicious content can also be hosted on whitelisted domains and I'd feel a lot better if I knew you were also investigating and fixing the root of the problems (the vulnerability to Cross-Domain Scripting) and not just fixing the symptoms.

(Reply to this) (Thread)(Expand)


[info]coffeechica
2009-09-23 02:54 pm UTC (link)
Absolutely -- we're discussing internally a few options more secure than whitelisting that will prevent this from happening in the future.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]franzi1981, 2009-09-23 02:56 pm UTC (Expand)
(no subject) - [info]polydad, 2009-09-23 03:03 pm UTC (Expand)
(no subject) - [info]idonotlikepeas, 2009-09-23 03:20 pm UTC (Expand)
(no subject) - [info]low_delta, 2009-09-24 03:09 am UTC (Expand)
(no subject) - [info]neosinific, 2009-09-24 07:13 am UTC (Expand)
(no subject) - [info]bateleur, 2009-09-26 01:43 pm UTC (Expand)
(no subject) - [info]astronewt, 2009-09-23 08:35 pm UTC (Expand)
(no subject) - [info]franzi1981, 2009-09-24 07:22 am UTC (Expand)

[info]janetmiles
2009-09-23 12:49 pm UTC (link)
Thanks for figuring this out and stopping it. I was one of the affected users.

I have edited the affected entry to remove the "Sorry" boxes and make it private again.

(Reply to this)


[info]littlestarletta
2009-09-23 12:50 pm UTC (link)
this happened to me :(

(Reply to this)


[info]angelus2hot
2009-09-23 12:50 pm UTC (link)
Thank you for letting us know and being so quick to fix the problem.

(Reply to this)


[info]greenelephant
2009-09-23 12:50 pm UTC (link)
Is there anything that a user who has been affected by this exploit can/should do to protect his or her account at this point?

(Reply to this) (Thread)


[info]idonotlikepeas
2009-09-23 01:13 pm UTC (link)
There shouldn't be further risk to the account from this particular attack, since they blocked the flash that was performing it. Right now, the best thing you can do is fix the entries that were changed and help identify any of your friends that might have been affected as well.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]rocketeddy, 2009-09-23 01:57 pm UTC (Expand)
(no subject) - [info]idonotlikepeas, 2009-09-23 02:04 pm UTC (Expand)
(no subject) - [info]ladyvox, 2009-09-23 03:17 pm UTC (Expand)
(no subject) - [info]rocketeddy, 2009-09-23 03:36 pm UTC (Expand)
(no subject) - [info]ladyvox, 2009-09-23 03:54 pm UTC (Expand)
(no subject) - [info]sundayave, 2009-09-23 04:13 pm UTC (Expand)
(no subject) - [info]idonotlikepeas, 2009-09-23 04:17 pm UTC (Expand)
(no subject) - [info]ladyvox, 2009-09-23 04:36 pm UTC (Expand)
(no subject) - [info]ladyvox, 2009-09-23 04:33 pm UTC (Expand)
(no subject) - [info]sundayave, 2009-09-23 05:23 pm UTC (Expand)
(no subject) - [info]ladyvox, 2009-09-23 04:37 pm UTC (Expand)
(no subject) - [info]dreamaria, 2009-09-23 04:34 pm UTC (Expand)
(no subject) - [info]astronewt, 2009-09-23 05:28 pm UTC (Expand)
(no subject) - [info]griffen, 2009-09-23 06:28 pm UTC (Expand)
(no subject) - [info]astronewt, 2009-09-23 06:43 pm UTC (Expand)

(442 comments) - (Post a new comment)

Page 1 of 10
<<[1] [2] [3] [4] [5] [6] [7] [8] [9] [10] >>

Create an Account
Forgot your login or password?
Login w/ OpenID
English • Español • Deutsch • Русский…