LiveJournal's security team has disabled some media features on the blogging site after a quick-spreading worm stole user email addresses and caused entries designated as private to be available to everyone. The self-propagating exploit spread to users who were logged in and did nothing more than view a LiveJournal posting that …
Hah, I didn't know people still used livejournal!
Yet another reason why you should set up different email addresses for each website you sign up on. Over the past few days, that's Poundhost, Demon, and now Livejournal that have leaked their users email addresses.
Embeds for all domains but the offending one are re-enabled as of yesterday sometime, after the patch fixing it was pushed live.
I'm betting the 100 accounts number was an early guess; I'd guess 500-3000, based on the number of news post comments and how very easy it was to spread.
I missed getting hit by it because I didn't think to bring my laptop with me when I went out that night; by the time I was back, it was blocked.
- Breaking news: Google exec veep in terrifying SKY PLUNGE DRAMA
- Geek's Guide to Britain Kingston's aviation empire: From industry firsts to Airfix heroes
- Analysis Happy 2nd birthday, Windows 8 and Surface: Anatomy of a disaster
- Google CEO Larry Page gives Sundar Pichai keys to the kingdom
- Something for the Weekend, Sir? SKYPE has the HOTS for my NAKED WIFE