<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>OpenCouchSurfing.org &#187; hacks</title>
	<atom:link href="http://www.opencouchsurfing.org/tag/hacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.opencouchsurfing.org</link>
	<description>The campaign for a truly open CouchSurfing organisation</description>
	<lastBuildDate>Tue, 31 Jan 2012 08:57:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>CouchSurfing password security vulnerability</title>
		<link>http://www.opencouchsurfing.org/2009/11/21/couchsurfing-password-security-vulnerability/</link>
		<comments>http://www.opencouchsurfing.org/2009/11/21/couchsurfing-password-security-vulnerability/#comments</comments>
		<pubDate>Sat, 21 Nov 2009 06:10:52 +0000</pubDate>
		<dc:creator>Callum</dc:creator>
				<category><![CDATA[Casey Fenton]]></category>
		<category><![CDATA[Jim Stone]]></category>
		<category><![CDATA[tech]]></category>
		<category><![CDATA[couchsurfing]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.opencouchsurfing.org/?p=493</guid>
		<description><![CDATA[Warning: If you get a username / password pop up on CouchSurfing.org, click cancel, do not enter your username and password except on the CouchSurfing login page. As of right now, I&#8217;m seeing this CSS file included on all CouchSurfing.org pages. That file links to this image. That image returns a 401 authorisation denied error. [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #ff0000;"><strong>Warning</strong>: If you get a username / password pop up on CouchSurfing.org, click cancel, do not enter your username and password except on the CouchSurfing login page.</span></p>
<p>As of right now, I&#8217;m seeing <a title="CouchSurfing CSS file including a security issue" href="http://www.couchsurfing.org/css/cs-indev.css?r=8995" target="_blank">this CSS</a> file included on all CouchSurfing.org pages. That file links to <a title="Problem image linked from CouchSurfing CSS file" href="http://www.functionalfreelance.com/cs/profile-verified-right-2-cap.gif" target="_blank">this image</a>. That image returns a 401 authorisation denied error. That in turn causes the browser to request a username and password, the realm is given as &#8220;CS&#8221;. If a user enters their CouchSurfing username and password, that data will be submitted to functionalfreelance.com.</p>
<p>This is a serious security issues as many users are likely to enter their passwords without realising what&#8217;s going on.</p>
<p>As far as I can tell from a scan of the whois data and dns records, there is no connection between couchsurfing.org and functionalfreelance.com. It seems likely to me that this is a hack of some sort, either deliberate or accidental. I hope accidental. Either way, this is a significant issue and needs immediate resolution by CS Inc. I have notified Casey Fenton, Jim Stone and Chris Burley directly of this issue.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opencouchsurfing.org/2009/11/21/couchsurfing-password-security-vulnerability/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

