Nav: Home
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 26, 2012, 10:05

Login with username, password and session length

MicrostockGroup

Microstockgroup Sponsors


« previous next »
Pages: [1] 2 Print

Topic: Istock down  

(Read 2814 times)
CvanDijk



« on: March 03, 2009, 21:20 »

I read on Nicolesy's facebook that Istockphoto is down:

RT @kkthompson: There is a phishing attack happening against iStockphoto. We've taken down the site as a precaution.

I hope it's not taking to long


Ignore | Logged


DepositPhotos.com
Graffoto



« Reply #1 on: March 03, 2009, 21:28 »

Well it has been down for at least an hour and a half at this point from when I first noticed it  Angry

My sales were not that great today... but now they are toast!
It of course really hurts people like Sean a lot more than little guys like me.

Still not fun though.


Ignore | Logged


disorderly


Dreamstime GaugeiStock Gauge
« Reply #2 on: March 03, 2009, 21:36 »

Boy, if I were exclusive, I'd be seriously pissed right about now...


Ignore | Logged


helix7


« Reply #3 on: March 03, 2009, 21:38 »

Boy, if I were exclusive, I'd be seriously pissed right about now...

Word...



Logged


KarenH


« Reply #4 on: March 03, 2009, 21:44 »

I feel for the IT guys there, probably a long night ahead of them. 


Ignore | Logged


gostwyck

Dreamstime GaugeiStock Gauge
« Reply #5 on: March 03, 2009, 21:45 »

Boy, if I were exclusive, I'd be seriously pissed right about now...

Why? That's simply the risk you take when you put all your eggs in one basket. It's hardly a surprise for IS to go down, it happens quite frequently, and it's something that any exclusive would obviously have factored into their calculation.


Ignore | Logged


Gregor909


Dreamstime GaugeiStock Gauge
« Reply #6 on: March 03, 2009, 21:49 »

Dam*n hackers. Shoot them all those miserable f*cks!  Angry


Ignore | Logged


helix7


« Reply #7 on: March 03, 2009, 22:14 »


They're back up.

Sounds like passwords may have been compromised. Might be a good time to change to a new one...



Logged


UncleGene



« Reply #8 on: March 03, 2009, 22:37 »

Very strange.
1. For a _real_ phishing attacks IS seems to be too small of a target. Big bad guys do not waste their time on something like this.
2. For _any_ type of phishing attack - how can taking site down help?

And to helix7 - phishing attacks compromise passwords only for those who got phished Smiley



Ignore | Logged


yingyang0

iStock Gauge
« Reply #9 on: March 03, 2009, 23:33 »

2. For _any_ type of phishing attack - how can taking site down help?
That's what I was thinking too.


Ignore | Logged


disorderly


Dreamstime GaugeiStock Gauge
« Reply #10 on: March 03, 2009, 23:41 »

Boy, if I were exclusive, I'd be seriously pissed right about now...

Why? That's simply the risk you take when you put all your eggs in one basket. It's hardly a surprise for IS to go down, it happens quite frequently, and it's something that any exclusive would obviously have factored into their calculation.

I wouldn't call that obvious at all.  Moreover, I bet there are a lot of exclusives who hadn't given it much thought before an incident like this.  Just because something can be predicted doesn't mean it will be, at least not by everybody.


Ignore | Logged


leaf
« Reply #11 on: March 04, 2009, 01:25 »

here is a link to the istock thread
http://www.istockphoto.com/forum_messages.php?threadid=85143


Ignore | Logged


araminta


Dreamstime GaugeiStock Gauge
« Reply #12 on: March 04, 2009, 02:43 »

2. For _any_ type of phishing attack - how can taking site down help?
That's what I was thinking too.

I'd guess it helps prevent hackers from using the stolen credentials and take the money.


Ignore | Logged


MichaelJay

iStock Gauge
« Reply #13 on: March 04, 2009, 03:27 »

2. For _any_ type of phishing attack - how can taking site down help?
That's what I was thinking too.
I'd guess it helps prevent hackers from using the stolen credentials and take the money.

Also apparently the fishing attack was somehow distributed through Forum posts and/or Sitemail, I have no details yet. So closing the site prevented further distribution of the problem.

Anyway, recommendation is to a) change your password on iStockphoto if you have doubts and b) check if you are using the same username/password combination of other sites. You might be vulnerable there as well.


Ignore | Logged


CraigSwatton

iStock Gauge
« Reply #14 on: March 04, 2009, 05:14 »

Boy, if I were exclusive, I'd be seriously pissed right about now...

Why? S**t happens and the attack could have happened anywhere, I'm just thankful and impressed istock dealt with it so quickly and efficiently.

Yes it might dent yesterday's sales but closing the site isolated the problem and stopped it becoming a major issue!


Ignore | Logged


sjlocke

iStock Gauge
« Reply #15 on: March 04, 2009, 07:25 »

Boy, if I were exclusive, I'd be seriously pissed right about now...

Yeah, I don't understand this either.  It wasn't their fault and it was dealt with.  A small downtime is just a part of business.


Ignore | Logged


Vonkara



« Reply #16 on: March 04, 2009, 09:30 »

OMG I was constantly logged out of Istock yesterday, like someone was loggin in from another computer.  Huh


Ignore | Logged


UncleGene



« Reply #17 on: March 04, 2009, 10:38 »

Very strange.
1. For a _real_ phishing attacks IS seems to be too small of a target. Big bad guys do not waste their time on something like this.
2. For _any_ type of phishing attack - how can taking site down help?

And to helix7 - phishing attacks compromise passwords only for those who got phished Smiley



Correction. As they say it was from forums ans sitemail, they did not have phishing attack. It was XSS exploit, and yes, everybody should change passwords (though who knows how many XSS holes they still have)


Ignore | Logged


sjlocke

iStock Gauge
« Reply #18 on: March 04, 2009, 12:10 »

Correction.  It was links sent to members in sitemail an forums, so it was just phising, and not whatever xss stuff you're talking about.


Ignore | Logged


Gregor909


Dreamstime GaugeiStock Gauge
« Reply #19 on: March 04, 2009, 12:12 »

If our passwords are really out there...why doesn't Istock inform us about this. There are so many contributors who never read the forums!


Ignore | Logged


digiology


« Reply #20 on: March 04, 2009, 12:39 »

I got a warning notice from Lookstat to change my passwords last night, but nothing from IS now that you mention it.  Undecided

and what is XSS anyway?

Logged


UncleGene



« Reply #21 on: March 04, 2009, 12:40 »

Correction.  It was links sent to members in sitemail an forums, so it was just phising, and not whatever xss stuff you're talking about.

Are you absolutely sure? The difference is simple: if it was phishing, only ones who used these links are in a bad shape; in case of xss - anybody who visited the site.


Ignore | Logged


UncleGene



« Reply #22 on: March 04, 2009, 12:44 »

I got a warning notice from Lookstat to change my passwords last night, but nothing from IS now that you mention it.  Undecided

and what is XSS anyway?

In simple words:
Phishing - you are tricked to go to different site
XSS - somebody puts the code on IS that (may) share all your data

You can defend yourself from (1) by never using insecure login on IS (do not use one on top of the page, go to a separate login page, and always check "secure" icon in your browser), but the only defense from (2) is to disable javascript - and this in turn will make IS unusable.


Ignore | Logged


Vonkara



« Reply #23 on: March 04, 2009, 12:57 »

This attack created a fake istockphoto.com login screen, prompted the user for a username & password, saved them to a malicious server, then redirected the user back to the iStockphoto main page.
   

http://www.istockphoto.com/forum_messages.php?threadid=85143    From leaf post earlier

Does this help?
« Last Edit: March 04, 2009, 12:59 by Vonkara »

Ignore | Logged


RacePhoto



« Reply #24 on: March 04, 2009, 13:22 »

This attack created a fake istockphoto.com login screen, prompted the user for a username & password, saved them to a malicious server, then redirected the user back to the iStockphoto main page.
   

http://www.istockphoto.com/forum_messages.php?threadid=85143    From leaf post earlier

Does this help?


Yes, because in simple terms, only people who logged in to the fake site are at risk, no one else!

This afternoon a phishing attack was conducted in the forums and through sitemail. This attack created a fake istockphoto.com login screen, prompted the user for a username & password, saved them to a malicious server, then redirected the user back to the iStockphoto main page.

Unless you logged in to forums or sitemail, during the afternoon, there's nothing to panic about.

I have a different password for each agency, which is a good idea if you want to make yourself fell better, should someone actually break into a database. I have a notebook with my passwords, so I don't forget them.  Grin Could just be a sign of old age?


Ignore | Logged


Microstock InsiderEnvateo Photo Tools
Pages: [1] 2 Print 
« previous next »
Jump to:  


Related Topics
Subject Started by Replies Views Last post
istock down!?
iStockPhoto.com
leaf 2 2478 Last post July 25, 2006, 06:12
by leaf
iStock Stats - Where iStock ranks in Traffic, Files, Royalties & More
iStockPhoto.com
amanda1863 5 4537 Last post August 22, 2006, 15:49
by amanda1863
iStock in the top 300
iStockPhoto.com
CJPhoto 5 1246 Last post October 27, 2006, 12:10
by CJPhoto
iStock down?
iStockPhoto.com
yingyang0 3 970 Last post November 20, 2006, 19:19
by yingyang0
IStock, please..... enough....
iStockPhoto.com
stockastic 2 734 Last post August 07, 2009, 13:59
by willie

TinyPortal v1.0.5 beta 1© Bloc