Was Photobucket hacked?
Above: Photobucket down – site as seen by some users yesterday.

Photobucket was hacked yesterday, using what seems like a dns hack*
*see “what is a DNS hack?” at the bottom of this post.

Because the Photobucket outage was dns based, it meant that some people could still access the site, whilst others either got a hackers message, or a completely different website.

Users on discussion boards started debating the hacking with headlines like: “Was Photobucket site hacked?“, “Photobucket hacked!” and “!!!Photobucket.com Has Been Hacked!!!“… you get the picture. In other words, it was all over the Net, with screenshot evidence and some genuine concern from users about the ability of Photobucket to keep their content and payment details safe.

What concerns me most about this story isn’t actually the hack itself. What I find worrying is that Photobucket didn’t put their hands up and say: “yes, we were hacked, Photobucket was down” or “yes, we suffered a dns hack!” or even, “it appears that Photobucket suffered a dns hack, we are looking into it and will come back to you as soon as we know more”.

Instead what Photobucket did was:
a. say nothing on their blog.
b. say nothing on their site.
c. When users started discussing this on Photobucket’s own support forums, their admin came back with this:
“On Tuesday afternoon, some users that typed in the Photobucket.com URL were temporarily redirected to an incorrect page due to an error in our DNS hosting services. The error was fixed within an hour of its discovery, but due to the nature of the problem, some users will not have access to Photobucket for a few hours as the fix rolls out. It is important to note
that only a portion of Photobucket users encountered the problem and that no
Photobucket content, password information or other personal information was
affected by the redirect. ”

Photobucket response to Turkish Hacker incident

“due to an error in our DNS hosting services.”? An error, as in a technical error? One that happened to redirect users to a message from a Turkish hacker?

This is very old-school: ‘let’s not admit anything and hope for it to go away’. The problem is that on the Internet, you can’t use these sort of tactics anymore. Users have become more savvy, and they expect the kind of openness that Jeff Jarvis demanded from Dell, during his “Dell Hell” experience.

The key message here is: if you put your hands up and say – this is what went wrong, and here’s what we’re doing to fix it, users will trust you. If you don’t tell the truth and your customers suss you out, they will rightfully ask: ‘what else are they hiding from us?’ Would I know if my details ever got compromised? Why should I trust this company?

It’s still early hours – Photobucket, you could still issue a statement and tell us what has actually happened. Why was Photbucket down? Leave it longer, and your users might not be as forgiving.
UPDATE: Some two days have passed since this started, and still nothing official on the company’s website, nothing on its blog and nothing in the press area.

Still not able to access Photobucket? Click here for some help.

============================================
What is a DNS hack? A dns hack alters where your computer browser goes when you type in an Internet address. Every web address (like www.thatdanny.com) has a corresponding number like 66.118.156.62 which is its real address (like a telephone number). When you enter a URL, your browser goes to a directory (called dns-”domain name server”), which tells it what the number of the domain is, so that it can find and display it. Thus, if you can change an entry in the dns directory by hacking into it, you can cause users to go to a completely different website. This is what appears to have happened with Photobucket.

============================================
MORE PHOTOBUCKET INFORMATION:
For the latest updates – go here.
============================================

Technorati Tags: , , , , ,

Tagged with:
 

7 Responses to Photobucket hacked – and how not to handle your customers when you get hacked!

  1. Maynabelle says:

    They actually have said something about it and explained the situation.

  2. Danny says:

    As of writing, there is no message about this on the Photobucket homepage, there is nothing on their official blog and nothing in the press area. So, if they have explained somewhere, it isn’t anywhere that’s immediately obvious. And if it isn’t immediately obvious, then it is as good as not explained at all.

  3. CesarPeru says:

    Shame on you Photobucket Team!
    I rely on your capability in these last years and I actually enjoyed how conveniently I could write more creative emails with some images IN the body of the message lifted straight from my Photobucket account..
    Furthermore; I heavily use Photobucket for the different items that I list on eBay since the images uploaded in my Photobucket account remained in the same size and high resolution that I intended!

    Cesar

  4. [...] They won’t say anything more than that, but to be “temporarily redirected” to a Turkish Hacking groups page defacement due to an error in DNS hosting services is pretty, uh, unique? An interesting critique of the situation can be found here. [...]

  5. [...] Turkish hacker group NetDevilz. Reports spread in forums or discussion boards and security blogger posts. The Register also reported of the [...]

  6. [...] drew criticism for not acknowledging the hack. According to ThatDanny, PhotoBucket said nothing initially, then finally posted an announcement blaming “an error in [...]

  7. Everyone loves and apology and admission that one is only human.

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Please leave these two fields as-is:
Set your Twitter account name in your settings to use the TwitterBar Section.