On mySimon: Deadwood - The Complete Series
BNET Business Network:
BNET
TechRepublic
ZDNet

September 24th, 2008

Bill O'Reilly's web site hacked, attackers release personal details of users

Posted by Dancho Danchev @ 5:56 am

Categories: Hackers, Passwords, Pen testing, Phishing, Privacy

Tags: Bill O'Reilly, Sarah Palin, Wikileaks, Hacktivism, Hacking, Security, Dancho Danchev

Fox NewsIn what is slowly turning into a endless loop of hacktivism activities, Bill O’Reilly’s BillOreilly.com has been compromised during the weekend, with personal details including passwords in plain text for 205 of the site’s members already leaking across Internet forums, as a response to his remarks regarding Wikileaks as a “one of those despicable, slimy, scummy websites” which recently published private information of Sarah Palin’s private email.

On Friday, Wikileaks issued the following press release :

“Fox News demagogue, Bill O’Reilly, has been hacked and the details passed to Wikileaks. Wikileaks has been informed the hack was a response to the pundit’s scurrilous attacks over the Sarah Palin’s email story–including on Wikileaks and other members of the press, Hacktivists, thumbing their noses at the pundit, took control of O’Reilly’s main site, BillOReilly.com. According to our source, the security protecting O’Reilly’s site and subscribers was “non-existent”.

The following image, submitted to Wikileaks and confirmed by Wikileaks staff, offers proof of the hack. The image, clearly obtained from BillOreilly.com’s administrative interface, shows a detailed list — including passwords — of BillOreilly.com subscribers. Although Wikileaks has only released one page, it must be assumed that Bill O’Reilly’s entire subscriber list is, as of now, in the public domain.”

How did they do it “this time”?

According to the article at Wikileaks, the hacktivists seem to have been brute forcing the URL for the administration panel, and once successfully finding it, access the unencrypted data :

“According to Marston, the hackers were able to access the list by trying a large number of variations of the website’s administrative URL. He said all affected members have received an email and a phone call informing them of the breach and urging them to change their password. The site has since been completely locked down, Marston said.”

Moreover, it’s also worth pointing out that the passwords were stored unencrypted, evidence of the practice can also be seen within the screenshots of the admin panel. As far as the website’s administrative URL is concerned, it has since been changed once it leaked online (w3.billoreilly.com/pg/jsp/admin/managecustomers/newpremiummembers.jsp), which isn’t excluding the opportunity for abuse of the subscribers email addresses in spear phishing attacks, “for starters” since some of the users have already admitted of using the same password at different web sites, including PayPal.

The impact of the breach, and the measures taken to notify the victims according to the site :

“The BillOReilly.com site experienced a minor hacking incident on Friday, September 19th, 2008.

** ALL CREDIT CARD INFORMATION FOR EVERY MEMBER IS SAFE
** NO MEMBERS WHO JOINED BEFORE WEDNESDAY, SEPTEMBER 14th, 2008 WERE AFFECTED AT ALL.
** 205 new Premium Members who signed up last week had their name, hometown, email address, & BillOReilly.com password stolen.
** We have contacted those 205 members by email and telephone.
** We are working with the proper authorities to track down the perpetrators. “

Another personal message issued by Bill O’Reilly regarding the process of tracking down the “perpetrators” was posted on Sunday :

“The FBI and Secret Service are close to indicting some of the perpetrators and we will keep you posted when the arrests are made. All premium members receive the full backing of our legal team and if anyone is hassled in the least, please inform us immediately. In the latest case, no proprietary information was obtained by hackers and we have safeguards in place to protect everyone who does business with us.

Rest assured that we are on this. Our defense of Sarah Palin has led some criminals to attempt to disrupt our enterprise. At this moment federal authorites and our attorneys are compling information against these people. Again, if any person is bothered in any way - please let us know. We stand behind our products but, most importantly, we stand behind you. We’ll get the bad guys. Count on it.

Bill O’Reilly
9/21/08″

Who’s claimed responsibility? 4chan members planning at Ebaumsworld using “secret words” :

“According to my source this is a common tactic among the secret hacking group hidden amongst the users of ebaumsworld. he states “yeah we will start planning on 4chan so ebaums doesnt get in trouble…we use secret words and stuff to let the others know who we are” when i asked why he was telling me all this he said “man this has just gone too far.. at first it was a joke then we found out that the same usernames and passwords worked for those peoples paypal accounts and im afraid of what they will do.”

It appears that the “forum fraction” is also planning a DDoS attack against BillOreilly.com according to this interview, which wouldn’t be the first time the site has been under DDoS attack, and definitely not the last. From an analyst’s perspective, nation2nation hacktivism conflicts always provide the best and most accurate understanding of a particular’s country’s capabilities into this space, compared to hacktivism actions basically sticking to the standard practices as DDoS attacks, which just like any tip of the iceberg receive most of the attention due to the ease of measuring their impact next to the rest of the hacktivism tactics used.

The bottom line - good time to point out why you shouldn’t use the same password on different web services, and that the big picture having to do with Wikileak’s vision of a little less secrecy, and a little bit more transparency, ultimately better serves the world and gives power to the people whose collective consciousness, if not brainwashed, is supposed to be shaping the way we live.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 139 Talkback(s)
facepalm.jpg
Yet another misconception about us.

Anonymous is devoid of humanity, morality, pity, and mercy.
Anonymous works as one, because none of us are as cruel as all of us.
Anonymous is everyo... (Read the rest)
Posted by: maferious Posted on: 11/08/08  (Edited: 11/08/08 @ 10:50) You are currently: a Guest | | Terms of Use
You're Kidding with your "Bottom Line," Right?  PhillipMcKann | 09/24/08
Well of course it does!  irtehnonl33t:( | 09/24/08
Obvious troll  Frank Poole | 09/24/08
Conservatives?!  nothingness | 09/24/08
The only facist of late  rlatulippe@... | 09/24/08
Fascism  laura.b | 09/24/08
Oops that's not fascism  maldain | 09/24/08
Take that up  laura.b | 09/24/08
I love it when people remember history...  n00b-herder | 09/25/08
Thank you laura.b  bmerc | 09/25/08
thief  vilppuu@... | 09/25/08
Socialists?  kerouac | 09/25/08
Jack is that you?  n00b-herder | 09/25/08
Who wants that word...  ncimon@... | 09/29/08
Oh, for God's sake!  hawkeye96 | 09/29/08
Re: You're Kidding with your "Bottom Line," Right?  ddanchevZDNet Moderator | 09/24/08
That problem that will inevitably arise  GuidingLight | 09/24/08
Rebuttal  Confused by religion | 09/24/08
HIPPA Means nothing  GuidingLight | 09/24/08
ddanchev posting peoples personal information serves what purpose they are  SO.CAL Guy | 09/24/08
Re: ddanchev posting peoples personal information serves what purpose that  ddanchevZDNet Moderator | 09/24/08
Not activism just criminal  maldain | 09/24/08
"the part where they stole and published credit card numbers"  bmerc | 09/25/08
If you steal a box marked "PRIVATE" from someone's home.  invmgr@... | 10/27/08
How does this family recover. Will the stress affect her cancer recovery?  invmgr@... | 10/27/08
Prison time  gridley@... | 09/25/08
What value?  baconeer | 09/25/08
IGNORE the personal information leaked?  nancyjones36507@... | 09/29/08
Yeah, he totally said that didn't he?  bmerc | 09/25/08
The info terrorist video on YouTube ...  GreyGeek | 09/25/08
Just the Eyes Phillip?  ncharleyhardtail@... | 09/25/08
I guess clothes should be transparent  baconeer | 09/25/08
hackers  redracer22214 | 09/24/08
smalkl little people who hack and use the same escuse  DWFBAG | 09/25/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  edxxx@... | 09/24/08
No morality. It's dead!  btamxx | 10/09/08
Even the simple measure of IP limiting the admin panel would have worked  edxxx@... | 09/24/08
SOmething most management woyuld have to buy into.  rlatulippe@... | 09/24/08
Limiting by IP address by theory is good...  mystic100 | 09/25/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  Boomk1974 | 09/24/08
Wow...  Alicynx | 09/24/08
seem you resemble his remark. happy  SO.CAL Guy | 09/24/08
Alicynx, welcome to the world of manly men  bmerc | 09/25/08
A note to bmerc...  NtWkAdmin | 09/25/08
I agree  ccrashh2@... | 09/25/08
Duh  ccrashh2@... | 09/25/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  ccrashh2@... | 09/24/08
back to the stone age  Alicynx | 09/24/08
EYE for an EYE sounds great to me lock the criminals up  SO.CAL Guy | 09/24/08
eye for an eye!  seanferd | 10/27/08
Hmmmm  maldain | 09/24/08
Why, exactly?  laura.b | 09/24/08
Yeah, all hackers are left-wing...right!  MGP2 | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  irtehnonl33t:( | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of  Someguy2 | 09/24/08
RE: Bill O'Reilly's web site hacked  BrianAllan | 09/24/08
Shoot the lefty bastards?  n00b-herder | 09/25/08
Fire your informant for wrong information.  Frank Poole | 09/24/08
No, this isn't true at all.  Vael Victus | 09/24/08
haha, liar  Frank Poole | 09/24/08
RE: Bill O'Reilly's web site hacked  Incpens | 09/24/08
Speaking of hypocrites  d.esposito@... | 09/25/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  rcrcay | 09/24/08
Hmmm, let me get this straight  maldain | 09/24/08
It's illegal to beat someone up.  bmerc | 09/25/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  ZDcommentator | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of  ddanchevZDNet Moderator | 09/24/08
The release of peoples account and passwords ....  ShadeTree | 09/24/08
what?  Alicynx | 09/24/08
what what?  rlatulippe@... | 09/24/08
Because most users use the same password for everything.  bmerc | 09/25/08
Using the same password for everything is the problem  mystic100 | 09/25/08
If the standard is that alone,  nancyjones36507@... | 09/29/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  ZDcommentator | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  eye of the day | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  bytet@... | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of  ddanchevZDNet Moderator | 09/24/08
Is it just your background?  nancyjones36507@... | 09/29/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  rarvai@... | 09/24/08
Ha! Two words...  MGP2 | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  joan2067 | 09/24/08
HAH  Annondelivers | 09/24/08
jail time  rlatulippe@... | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  Linux User 147560 | 09/24/08
Neolibs ARE nazis and just don't know it.  binthere222 | 09/24/08
actually,  vilppuu@... | 09/25/08
Re: actually,  GreyGeek | 09/25/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  ddanchevZDNet Moderator | 09/24/08
Wikileaks = cyber extortionist.. if you say anything about us we will have  SO.CAL Guy | 09/24/08
Re: Wikileaks = cyber extortionist.. if you say anything about us we will h  ddanchevZDNet Moderator | 09/24/08
Responsible Journalism  SinisterMatt | 09/24/08
How stupid an opinion is that?  ccrashh2@... | 09/25/08
Gosh ccrash, you mean just like YOU did?  bmerc | 09/25/08
So very simple-minded...  ccrashh2@... | 09/25/08
Is your defense of wickedleaks personal?  baconeer | 09/25/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  trixlette | 09/24/08
hacktivists = criminals. we really need new laws to lock these morons up  SO.CAL Guy | 09/24/08
Re: hacktivists = criminals. we really need new laws to lock these morons u  ddanchevZDNet Moderator | 09/24/08
fraud? what fraud?  vilppuu@... | 09/25/08
hacktivists=criminals  n00b-herder | 09/25/08
The Left is afraid!!  techboy_z | 09/24/08
Left is not afraid... thankfully I'm ambidextrous.  n00b-herder | 09/25/08
No, liberals want no boundaries  Aragorn_z | 09/29/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  me5 | 09/24/08
not fascists. anarchists!  Agent Smith Jr. | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  pottspotts | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  Osamas Pajamas | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  kaw kay shion | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  Curly42 | 09/24/08
RE: from ebaums with love. Part 1 of 5  ericbauman | 09/24/08
Part 2  ericbauman | 09/24/08
Part 3  ericbauman | 09/24/08
Part 4  ericbauman | 09/24/08
Part 5  ericbauman | 09/24/08
YAWN at obvious and lame trolling  bmerc | 09/25/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of  jrg5067 | 09/24/08
RE: "Hacktivists"?  Zabeus | 09/24/08
RE: Bill O'Reilly's web site hacked  John Karl | 09/24/08
They sound like terrorists, but its hard to feel sorry for Bill O  T1Oracle | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  johnfranks999 | 09/24/08
typical radical tactics...  jtyrrell@... | 09/24/08
Legion  amaduli | 09/24/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of  vilppuu@... | 09/25/08
Is anybody really surprised?  BitterClinger | 09/25/08
Minor correction  n00b-herder | 09/25/08
Lame, ignorant, baseless, politicizied, trolling. Typical :\ nt  T1Oracle | 09/29/08
Why the hell has ccrash not been permanently banned?  bmerc | 09/25/08
Are you nuts?  ccrashh2@... | 09/25/08
Cyberwar  quuzlfut@... | 09/25/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  ZDNET_guest666 | 09/25/08
Bi-Partisan Responsibilities  gridley@... | 09/25/08
What is the democrat opposing point of view?  ZDNET_guest666 | 09/25/08
Never?  djchandler | 09/25/08
NO RESPECT  nancyjones36507@... | 09/29/08
I think Bill O the clown is a piece of...  nix_hed | 09/29/08
We don't need more laws for this  Dr_Zinj | 10/09/08
RE: Bill O'Reilly's web site hacked, attackers release personal details of users  btamxx | 10/09/08
facepalm.jpg  maferious | 11/08/08
Capital Punishment, starting with the kid that jacked the Palin Family.  invmgr@... | 10/27/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here