RIAA website gets hacked by SQL injection
The site appears to be operating fine now, but we noticed it certainly wasn't fine yesterday (and TorrentFreak has screenshots of the site, sans content). Is it ironic that the RIAA uses free open-source software (OSS) such as PHP to run their website while hunting down people who allegedly don't pay for music? You'd expect something more sinister, like Karl Rove hand typing HTML pages in a dimly lit sarcophagus or, at least MS SQL/IIS.
If only they spent more time working to save themselves from cross-site scripting attacks and SQL injection instead of going after college students for downloading "My Humps."
[Via TorrentFreak]













Comments
10
Subscribe to commentsAlexMar 11th 2008 5:18AM
RIAA had it coming.
Kudos to the brave citizens involved. All hail little Bobby Tables!
DrWatsonJan 21st 2008 10:27PM
I respectfully disagree with the comments/joke pairing commercial software with RIAA. While some of us may find non-open-source software harmful and debatable, the RIAA is the devil itself and should be forced to code their website in Perl with Oracle.
AlexLJan 21st 2008 10:30PM
"Is it ironic that the RIAA uses free open-source software (OSS) such as PHP to run their website while hunting down people who allegedly don't pay for music?"
No, it's not ironic at all. RIAA isn't violating the terms of the licenses of the open source software when they use it to power their website.
Todd RitterJan 22nd 2008 7:01AM
My point was not that they were violating any license. My point was simply that they were using free software...that is, using something without paying for it much like they accuse thousands of people for doing with music.
Fred ThompsonJan 21st 2008 11:16PM
Agree, this looks like a hack post from Slashdot or KOS. Political commentary is like boudoir photography. Leave it to the professionals. It's really ugly when amateurs try it.
catchwaJan 22nd 2008 4:26AM
What AlexL said...
get a dictionary Todd
skafiJan 22nd 2008 4:58AM
is it a shame if an important company used free open-source as php? i dont think so..and if a bug was in the code that doesnt mean that u wont find bugs under another programming language like asp.it depends on how the webdevelopper wrtiting the code and protect his website....
captain underpants and the bringdown gangJan 22nd 2008 8:52AM
too bad they couldn't get admin access and change the password thus preventing the RIAA from coming back.
flipthefrogJan 22nd 2008 11:09AM
The creators of the software are the ones to decide that it will be released under an OpenSource license, not the users.
The creators of the music are the ones to decide if it will be released by a record company or "opensource", not the listeners
I see no irinoy at all. Only half formed ideas and hypocritical thinking
AlexLJan 22nd 2008 1:38PM
Todd, The RIAA isn't going after people for simply "using something without paying for it", they are going after people for violating the terms of the licenses of the music it oversees.