RIAA Website Wiped Clean by “Hackers”

Written by Ernesto on January 20, 2008 

Apparently the RIAA is so busy suing consumers that they forgot to hire a decent programmer. With a simple SQL injection, all their propaganda has been successfully wiped from the site.

It started out on the social news website Reddit, where a link to a really slow SQL query was posted. While the Reddit users were trying to kill the RIAA server, someone allegedly decided to up the ante and wipe the site’s entire database.

The comments on Reddit are only speculation so far. Based on the username, which was apparently “webReadOnly”, it might not have been setup correctly, or someone could have found another way to delete the content form the site.

Another possibility is that the website has some sort of database flood protection that disables new connections, or perhaps the RIAA themselves removed the content temporarily. The latter seems unlikely, as a better solution would be to take it entirely offline to fix the bigger problem. While they could fix a small vulnerability like this in a matter of seconds, the chances are it’s not an isolated problem.

As pointed out by Haywire, playing around with the urls a bit can return some funny results. It is pretty easy to make the RIAA link to The Pirate Bay for example.

For now it sure does look like all the content has been wiped from the RIAA homepage. Let’s hope they have backups, or not.

Update: After a few hours the RIAA restored the site. They seem to have fixed the vulnerability, but we have saved some screenshots.

Update: They didn’t fix it all, this still works.

RIAA website without content

riaa

RIAA supporting The Pirate Bay

riaa pirate bay

Error?

riaa error

Previously: Music Industry Got An Injunction Against Rapidshare in 2007, Site Not Shut Down

Next: Most Popular DVDrips on BitTorrent (wk3)

241 Responses (Add yours or TrackBack)

Pages: « 1 [2] 3 4 5 6 7 8 9 10 » Show All

26 Jan 20, 2008 at 18:00 by Crandom

W00t W00t taken DOWN!

27 Jan 20, 2008 at 18:00 by capiCrimm

it’s not wiped. The db is simply flooded from all the long reddit queries to the point that it can’t make any new connections. If you load the page about fifty times you’ll get lucky and see the data now and then.

28 Jan 20, 2008 at 18:04 by Anonymous

wut happens 2012?

29 Jan 20, 2008 at 18:05 by swisha

The Punks vs Mercs battle is really heating up lately, and the reds are winning :P

30 Jan 20, 2008 at 18:05 by awesome

haha, pwned!

31 Jan 20, 2008 at 18:11 by Anonymous

Don’t f**k with 1337 h4×0r$

32 Jan 20, 2008 at 18:13 by Anonymous

this made my day! :)

33 Jan 20, 2008 at 18:26 by oneplusone

[quote comment="268190"]Your time is coming. Just wait until late 2012, you’ll see what we mean.[/quote]

Suck a dick.

34 Jan 20, 2008 at 18:38 by OPP

[quote comment="268190"]Your time is coming. Just wait until late 2012, you’ll see what we mean.[/quote]

2012? So THAT’S when you make your move for world domination and set up concentration camps for pirates. Might aswell build a fence around Earth.

35 Jan 20, 2008 at 18:42 by Death

[quote comment="268190"]Your time is coming. Just wait until late 2012, you’ll see what we mean.[/quote]

You should be executed for lameness.

36 Jan 20, 2008 at 18:44 by zach

end of the mayan calander. we dont know what will happen but something…. maybe it will rain? maybe a comet will hit? maybe the big mac will go onto the dollar menu?? ok thats pushing it..

37 Jan 20, 2008 at 18:45 by Anonymous

Yep, they’re definately off-line. (snicker)

38 Jan 20, 2008 at 18:49 by Mr.Afghanistan

LoooOooOoooooooooooooooL
RIAA fucked up :)

get a life RIAA. find some good programmers to close the fuckin security holes.

XSS security shit is for kids, still you guys fucked up with XSS trick. LoL

any way. Good Luck :)
do google how to prevent XSS attacks :)

39 Jan 20, 2008 at 19:17 by Vash

Everyone go to thief.infernohost.net and download my proxy webbrowser, you can keep switching proxies to get them LOL!

40 Jan 20, 2008 at 19:22 by PiratePartyOperations

Oh, come on, guys… these poor RIAA saps don’t know they’re stupid, and I’m sure with their history of litigating everything that moves, they can’t attract a decent programmer to begin with. And they obviously don’t trust Google, or they’d know how to secure a database.

41 Jan 20, 2008 at 19:22 by Bob

RIAA should group up with Scientology and make the “Church of Stupid”..

42 Jan 20, 2008 at 19:24 by Dan

Awww….. too bad for them

43 Jan 20, 2008 at 19:30 by Anonymous

w00t! Top of front page of Digg!

44 Jan 20, 2008 at 19:32 by TheOneX

FUCK RIAA and MPAA !!!

This is great news and next websites should be mediasentry.com and media-defender.com etc

FUCK copyright and PRO SHARING!

45 Jan 20, 2008 at 19:33 by zach

its back up now!! damn!!!

46 Jan 20, 2008 at 19:34 by Cl1mh4224rd

[quote comment="268213"]it’s not wiped. The db is simply flooded from all the long reddit queries to the point that it can’t make any new connections. If you load the page about fifty times you’ll get lucky and see the data now and then.[/quote]

I can confirm that this seems to be the case.

47 Jan 20, 2008 at 19:34 by zach

but its still wiped clean :)

48 Jan 20, 2008 at 19:36 by c17fm

nice hackers..

fuk the RIAA/MPAA

AND THIER BULLSHIT…

FREEDOM OF DL

49 Jan 20, 2008 at 19:40 by Anonymous

[quote comment="268190"]Your time is coming. Just wait until late 2012, you’ll see what we mean.[/quote]
don’t notice anything about 2012 that wikipedia says about that year.

50 Jan 20, 2008 at 19:43 by sevendegrees

:looks at headlines:

……

………

holy shit!!1! XD

Pages: « 1 [2] 3 4 5 6 7 8 9 10 » Show All

Add your response

It takes approximately 1 minute for your comment to appear on TorrentFreak after it's posted.