<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Telegraph.co.uk hacked &#8211; when will they learn?</title>
	<atom:link href="http://www.hackersblog.org/2009/05/29/telegraphcouk-hacked-when-will-they-learn/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hackersblog.org/2009/05/29/telegraphcouk-hacked-when-will-they-learn/</link>
	<description>United</description>
	<lastBuildDate>Sun, 07 Mar 2010 13:20:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: David</title>
		<link>http://www.hackersblog.org/2009/05/29/telegraphcouk-hacked-when-will-they-learn/comment-page-1/#comment-2603</link>
		<dc:creator>David</dc:creator>
		<pubDate>Wed, 03 Jun 2009 22:54:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.hackersblog.org/?p=2369#comment-2603</guid>
		<description>Did they reply already??</description>
		<content:encoded><![CDATA[<p>Did they reply already??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Эпидемия уязвимостей на британских сайтах - Персональный блог Вороны Богдана</title>
		<link>http://www.hackersblog.org/2009/05/29/telegraphcouk-hacked-when-will-they-learn/comment-page-1/#comment-2589</link>
		<dc:creator>Эпидемия уязвимостей на британских сайтах - Персональный блог Вороны Богдана</dc:creator>
		<pubDate>Wed, 03 Jun 2009 04:54:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.hackersblog.org/?p=2369#comment-2589</guid>
		<description>[...] одновременно с отчетом XSSed сайт HackersBlog опубликовал детали уязвимости к SQL-инъекциям, которую команда его хакеров обнаружила [...]</description>
		<content:encoded><![CDATA[<p>[...] одновременно с отчетом XSSed сайт HackersBlog опубликовал детали уязвимости к SQL-инъекциям, которую команда его хакеров обнаружила [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: keane</title>
		<link>http://www.hackersblog.org/2009/05/29/telegraphcouk-hacked-when-will-they-learn/comment-page-1/#comment-2500</link>
		<dc:creator>keane</dc:creator>
		<pubDate>Fri, 29 May 2009 14:01:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.hackersblog.org/?p=2369#comment-2500</guid>
		<description>Hi Guys 

It seems you guys have been looking further into this. I am unsure at what capacity however i am now in contact with the Telegraph so would be greatful to have your insight into the situation and maybe look to recruit your expertise to resolve it, as they are keen to sort this asap.

Please do contact me dkhendy509@hotmail.co.uk

Thanks,
Daniel</description>
		<content:encoded><![CDATA[<p>Hi Guys </p>
<p>It seems you guys have been looking further into this. I am unsure at what capacity however i am now in contact with the Telegraph so would be greatful to have your insight into the situation and maybe look to recruit your expertise to resolve it, as they are keen to sort this asap.</p>
<p>Please do contact me <a href="mailto:dkhendy509@hotmail.co.uk">dkhendy509@hotmail.co.uk</a></p>
<p>Thanks,<br />
Daniel</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: unu</title>
		<link>http://www.hackersblog.org/2009/05/29/telegraphcouk-hacked-when-will-they-learn/comment-page-1/#comment-2498</link>
		<dc:creator>unu</dc:creator>
		<pubDate>Fri, 29 May 2009 13:11:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.hackersblog.org/?p=2369#comment-2498</guid>
		<description>Jay...1. If you read the article carefully, you noticed that I did mention I wrote them emails but to no avail. I asked to speak to someone in their IT dept. ( I even wrote to  Paul Cheesbrough) and still got no answer
 2. In vain you still hope that the injection didnt give full access to users data  on the site. I have to dissapoint you. DB5_data it the main data base. The one that has all the data of the users. Accessing this DB you can access the clients. If you look closely, you can see in the the first article on hackersblog http://www.hackersblog.org/2009/03/06/telegraphcouk-hacked-sql-injection/) that DB5_data is the name of one of those databases. That same database is circled in the image in this article.If that database belonged to the Telegraph back then, I dont see how it could belong to someone else now. Especially since we talk about a subdomain of telegraph.co.uk.</description>
		<content:encoded><![CDATA[<p>Jay&#8230;1. If you read the article carefully, you noticed that I did mention I wrote them emails but to no avail. I asked to speak to someone in their IT dept. ( I even wrote to  Paul Cheesbrough) and still got no answer<br />
 2. In vain you still hope that the injection didnt give full access to users data  on the site. I have to dissapoint you. DB5_data it the main data base. The one that has all the data of the users. Accessing this DB you can access the clients. If you look closely, you can see in the the first article on hackersblog <a href="http://www.hackersblog.org/2009/03/06/telegraphcouk-hacked-sql-injection/)" rel="nofollow">http://www.hackersblog.org/2009/03/06/telegraphcouk-hacked-sql-injection/)</a> that DB5_data is the name of one of those databases. That same database is circled in the image in this article.If that database belonged to the Telegraph back then, I dont see how it could belong to someone else now. Especially since we talk about a subdomain of telegraph.co.uk.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blackie</title>
		<link>http://www.hackersblog.org/2009/05/29/telegraphcouk-hacked-when-will-they-learn/comment-page-1/#comment-2496</link>
		<dc:creator>Blackie</dc:creator>
		<pubDate>Fri, 29 May 2009 12:04:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.hackersblog.org/?p=2369#comment-2496</guid>
		<description>Se pare ca au rezolvat problema.
Unu, asteptam a treia buba.</description>
		<content:encoded><![CDATA[<p>Se pare ca au rezolvat problema.<br />
Unu, asteptam a treia buba.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://www.hackersblog.org/2009/05/29/telegraphcouk-hacked-when-will-they-learn/comment-page-1/#comment-2494</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Fri, 29 May 2009 11:34:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.hackersblog.org/?p=2369#comment-2494</guid>
		<description>Can you confirm they&#039;ve fixed the problem now? :) And I stand behind my claim that it doesn&#039;t contain Telegraph&#039;s own user data.</description>
		<content:encoded><![CDATA[<p>Can you confirm they&#8217;ve fixed the problem now? <img src='http://www.hackersblog.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  And I stand behind my claim that it doesn&#8217;t contain Telegraph&#8217;s own user data.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexu`</title>
		<link>http://www.hackersblog.org/2009/05/29/telegraphcouk-hacked-when-will-they-learn/comment-page-1/#comment-2492</link>
		<dc:creator>Alexu`</dc:creator>
		<pubDate>Fri, 29 May 2009 11:10:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.hackersblog.org/?p=2369#comment-2492</guid>
		<description>Good job unu and HB ! :)</description>
		<content:encoded><![CDATA[<p>Good job unu and HB ! <img src='http://www.hackersblog.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pyro</title>
		<link>http://www.hackersblog.org/2009/05/29/telegraphcouk-hacked-when-will-they-learn/comment-page-1/#comment-2491</link>
		<dc:creator>Pyro</dc:creator>
		<pubDate>Fri, 29 May 2009 11:09:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.hackersblog.org/?p=2369#comment-2491</guid>
		<description>Urmeaza a 3 oara? (cica e cu noroc atunci) =))</description>
		<content:encoded><![CDATA[<p>Urmeaza a 3 oara? (cica e cu noroc atunci) =))</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: keane</title>
		<link>http://www.hackersblog.org/2009/05/29/telegraphcouk-hacked-when-will-they-learn/comment-page-1/#comment-2489</link>
		<dc:creator>keane</dc:creator>
		<pubDate>Fri, 29 May 2009 10:12:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.hackersblog.org/?p=2369#comment-2489</guid>
		<description>Hi Jay,

I came across this thread and would like to discuss this with you in a bit more detail if you dont mind?

I work with both the Telegraph and the 3d party company i beleive you are referring. It would be good to understand the issue and see if there is anything i/we can do to resolve the issue. 

Please contact me on dkhendy509@hotmail.co.uk

Thanks</description>
		<content:encoded><![CDATA[<p>Hi Jay,</p>
<p>I came across this thread and would like to discuss this with you in a bit more detail if you dont mind?</p>
<p>I work with both the Telegraph and the 3d party company i beleive you are referring. It would be good to understand the issue and see if there is anything i/we can do to resolve the issue. </p>
<p>Please contact me on <a href="mailto:dkhendy509@hotmail.co.uk">dkhendy509@hotmail.co.uk</a></p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://www.hackersblog.org/2009/05/29/telegraphcouk-hacked-when-will-they-learn/comment-page-1/#comment-2482</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Fri, 29 May 2009 02:19:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.hackersblog.org/?p=2369#comment-2482</guid>
		<description>Hmm I doubt it however I do not argue it cannot be true. The DB names you&#039;ve listed are clients of the company responsible for the vulnerability. Seems to me that this subdomain provides some iframes for Telegraph along with other websites (hence those other DB databases listed) for the company responsible.
If you contacted Telegraph, would you mind describing what was their response this time?</description>
		<content:encoded><![CDATA[<p>Hmm I doubt it however I do not argue it cannot be true. The DB names you&#8217;ve listed are clients of the company responsible for the vulnerability. Seems to me that this subdomain provides some iframes for Telegraph along with other websites (hence those other DB databases listed) for the company responsible.<br />
If you contacted Telegraph, would you mind describing what was their response this time?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
