RIAA Website Wiped Clean by “Hackers”
Apparently the RIAA is so busy suing consumers that they forgot to hire a decent programmer. With a simple SQL injection, all their propaganda has been successfully wiped from the site.
It started out on the social news website Reddit, where a link to a really slow SQL query was posted. While the Reddit users were trying to kill the RIAA server, someone allegedly decided to up the ante and wipe the site’s entire database.
The comments on Reddit are only speculation so far. Based on the username, which was apparently “webReadOnly”, it might not have been setup correctly, or someone could have found another way to delete the content form the site.
Another possibility is that the website has some sort of database flood protection that disables new connections, or perhaps the RIAA themselves removed the content temporarily. The latter seems unlikely, as a better solution would be to take it entirely offline to fix the bigger problem. While they could fix a small vulnerability like this in a matter of seconds, the chances are it’s not an isolated problem.
As pointed out by Haywire, playing around with the urls a bit can return some funny results. It is pretty easy to make the RIAA link to The Pirate Bay for example.
For now it sure does look like all the content has been wiped from the RIAA homepage. Let’s hope they have backups, or not.
Update: After a few hours the RIAA restored the site. They seem to have fixed the vulnerability, but we have saved some screenshots.
Update: They didn’t fix it all, this still works.
RIAA website without content

RIAA supporting The Pirate Bay

Error?


Pingback: Support this story on Stirrdup
Pingback: Hyper123.net » Blog Archive » RIAA Website Wiped Clean by "Hackers"
Pingback: Dekut.com
Pingback: [TorrentFreak] RIAA Website Wiped Clean by “Hackers” - Overclock.net - Overclocking.net
Pingback: The RIAA website just got owned by hackers! - Head-Fi: Covering Headphones, Earphones and Portable Audio
Pingback: RIAA Website hacked. - Mind If I Do A J?
Pingback: Clouds gather at Pirate Bay - TechEnclave
Pingback: RIAA wiped off the net : Welcome To Tech-Dump
Pingback: RIAA wiped off the net - Computer Forums
Pingback: Off The Wall Question - WickedFire - Affiliate Marketing Forum - Internet Marketing Webmaster SEO Forum
Pingback: RIAA Website Wiped Clean by “Hackers” - The Prophecy Forums
Pingback: SQL Injection still works - Dennis van der Stelt
Pingback: Dilithium Crystalworks
Pingback: HAFFLEHOSS » RIAA Website Wiped Clean by Hackers
Pingback: RIAA Website Hacked
Pingback: UriShare - Riaa website wiped clean by hackers
Pingback: RIAA 网站被黑 | 天涯望月
Pingback: RIAA Website Wiped Clean by "Hackers" - Tire Resources - Tires Resources
Pingback: RIAA Hacked !! - TechWorldSpace
Pingback: RIAA supports Pirate Bay! | zero.gr
Pingback: RIAA Website Hacked - Beast Toast
Pingback: RIAA website hacked by SQL injection! - TORRENTs.RO
Pingback: HotstickyBun » Blog Archive » 19 - The RIAA Gets Hacked
Pingback: The Inquirer ES : La web de la RIAA, hackeada