News.com Mobile
for PDA or phone
Login: Forgot password? | Sign up

Firefox promo site taken down by hackers

By Joris Evers
Staff Writer, CNET News.com
Published: October 4, 2005, 10:55 AM PDT

Spread Firefox, the marketing Web site for the open-source Firefox Web browser, has been hacked again and is expected to be offline until later this month.

The cyber break-in was discovered this week, according to a notice sent Tuesday by the Spread Firefox team to registered users of the Web site. The breach was limited to SpreadFirefox.com and did not affect the main Mozilla.org Web site or Mozilla software, according to the e-mailed message.

Spread Firefox place holder

The server that hosts the Spread Firefox Web site was compromised by attackers who attempted to exploit a security vulnerability in TWiki, according to the notice. TWiki is open-source software for the collaborative authoring of online pages called "wikis".

This is the second time the site has been hacked via a flaw in software used to run the Web site. In July, the marketing site was compromised by attackers who exploited an unpatched security hole in PHP. The Drupal content management system used by the site is written in the PHP scripting language.

After the July attack, Mozilla instituted procedures to ensure that it would not overlook any more security fixes. "Unfortunately, those procedures overlooked the installation of the TWiki software, since it is not used by the main Spread Firefox site," the Spread Firefox team said in its notice.

The Firefox marketing Web site has been taken offline and will be rebuilt from scratch, according to the e-mail. "When the system is rebuilt, all the software will be audited to ensure that security updates will be applied in a timely manner," the team wrote.

The latest attack likely did not expose any user information, according to the e-mail. Still, people should change their password when the site comes back online, the team suggested. Spread Firefox's Web site should be back online circa Oct. 15, according to a notice on the site.

The hack is an additional embarrassment to Mozilla, which has emphasized security as a main selling point for its Firefox Web browser.

Spread Firefox is the online Firefox marketing hub. Mozilla has successfully used the site to mobilize volunteers to popularize the browser through free marketing techniques such as Web site buttons and by collecting money for an ad in The New York Times.

 23 comments
Post a comment

TalkBack

Asa Dolter is a tool

Newsdotcom Commenter   Oct 4, 2005, 7:23 PM PDT

Open Source hacked again

Grug 2005   Oct 4, 2005, 1:20 PM PDT

WHAT'S SO NEW ABOUT THIS

Satish Bhardwaj   Oct 4, 2005, 12:48 PM PDT

Well...

Matthew Good   Oct 4, 2005, 11:41 AM PDT

Are their admins the same people that ...

Nathar Leichoz   Oct 4, 2005, 11:37 AM PDT

advertisement

Did you know?

Select a tab below to set your default view.

Scan the 15 newest and most read stories on News.com right now. Learn more

Updated: 9:31 AM PST
View as:
Google whistles a new tune Compliance laws boosting IT budgets A chair with video-game vibe How to lose friends and alienate people Microsoft sues nine MAPS partners Is Stern worth his millions? Faux Hulks can keep fighting evil online 'King Kong' not so mighty on Xbox 360, standard TVs Google home pages get even more personal Quanta to build the $100 laptop Bringing prime time to video iPod Visto sues Microsoft for patent infringement Does Google have an ear for Opera? Photos: A vibrating chair for gamers  OpenDocument discussion veers toward consumers
Legend:
Older
Newer
Larger boxes indicate hotter stories.

Resource center from News.com sponsors

Concerned About Computer Security?

Education is the best defense

Computer security threats are part of daily life. But today's malware techniques present unprecedented challenges for businesses of all sizes. Learn how to protect yourself.

Learn from the experts>>

Top picks from News.com readers


Daily spotlight

Perspective: How to lose friends and alienate people

Law professor Tim Wu sees tech companies making wrong choices when it comes to their customers.

Bringing prime time to the video iPod

NBC's and TiVo's future plans aside, software allows users to take their recorded TV shows with them today.
Video: New content for iPod

Is Stern worth his millions?

Satellite radio will likely make back Stern's $500 million paycheck, but his post-decency patter remains a wild card.
Audio: Will Stern fly?

New 'Kong' monkeys with game industry

Peter Jackson's "King Kong" and the new movie-based game are blurring lines between where stories begin and end.
Video: Kong vs. T-Rex
Images: A beast of a game

Quanta to build the $100 laptop

World's largest laptop manufacturer will make the low-cost box championed by Massachusetts Institute of Technology.

Perspective: Holiday shoppers, beware

Attorney Eric J. Sinrod warns of an imminent parade of horribles: identity theft, viruses, phishing, worms and spyware.

Photo: The 'Urge' to play Xbox

Nissan's plans for its Urge Concept sports car include a built-in Xbox gaming system.

Keyboard carpal culprit?

Not so, study says A new research report says heavy computer use does not lead to carpal tunnel syndrome.

RFID goes to college

Indiana University, University of California at Irvine add business courses in electronic-identification technology.

Photos: Xbox 360 lands in Japan

Microsoft brings its next-generation game console to the home turf of rivals Sony and Nintendo.

Photos: Asimo learns new tricks

Honda's humanoid robot is faster than ever and ready to help out around the office.

Year in review: Data security

High-profile hack of Paris Hilton's phone and a huge credit-card leak brought worries over ID theft to the fore.


CNET.com
Copyright ©2005 CNET Networks, Inc. All Rights Reserved. Privacy Policy | About CNET Networks | Jobs | Terms of Use