Posted July 15, 2013
timppu: GOG forums were hacked too! I recall some people making new topics with special characters and shit that broke the forum! Damn that was scary.
Not so much hacked, but just a braindead move by whoever was maintaining the GOG forums in that output wasn't being sanitized, so people could input html in topics or thread titles and it would be rendered as html rather than text. Still a bad situation, and potentially quite a bit more dangerous for users visiting the forums. I'm not sure how much weight this carries anymore, as some of the recent DoD hacks (e.g. McKinnon) were due to default passwords being used on key pieces of equipment. Now, there are probably some very skilled individuals out there that can defeat very good security if they put their minds to it, but the vast, vast majority of breaches are due to security failings leaving the systems vulnerable to fairly basic approaches (SQL injection, default passwords, unpatched vulnerabilities, and good old social engineering).