<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>GigaOM &#187; Hacked</title>
	<atom:link href="http://gigaom.com/tag/hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://gigaom.com</link>
	<description></description>
	<lastBuildDate>Sun, 19 May 2013 20:32:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='gigaom.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/0db8f6557d022075dbbf010c54d46d93?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>GigaOM &#187; Hacked</title>
		<link>http://gigaom.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://gigaom.com/osd.xml" title="GigaOM" />
	<atom:link rel='hub' href='http://gigaom.com/?pushpress=hub'/>
		<item>
		<title>Holes in the Walled Garden: Has the App Store Been Hacked?</title>
		<link>http://gigaom.com/2010/07/05/holes-in-the-walled-garden-has-the-app-store-been-hacked/</link>
		<comments>http://gigaom.com/2010/07/05/holes-in-the-walled-garden-has-the-app-store-been-hacked/#comments</comments>
		<pubDate>Mon, 05 Jul 2010 19:45:12 +0000</pubDate>
		<dc:creator>Jon Buys</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[Appstore]]></category>
		<category><![CDATA[Hacked]]></category>
		<category><![CDATA[itunes]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=47951</guid>
		<description><![CDATA[This is a developing story, and not all of the facts are out yet, but if what is being reported on The Next Web turns out to be true, it may be prudent to stop reading and remove your credit card from your iTunes account.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=174367&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><img  title="app_store_icon" src="http://gigapple.files.wordpress.com/2009/04/app_store_icon.png?w=150&#038;h=150" alt="" width="150" height="150" class=" alignleft" />This is a developing story, and not all of the facts are out yet, but if what is being reported on <a href="http://thenextweb.com/apple/2010/07/04/app-store-hacked/comment-page-1">The Next Web</a> and by developer <a href="http://www.alexbrie.com/archives/205">Alexandru Brie</a> turn out to be true, it may be prudent to stop reading this now and remove your credit or debit card from your iTunes account.  I did, purely as a precautionary measure until this is sorted out.</p>
<p>The Next Web has been running a <a href="http://thenextweb.com/apple/2010/07/05/app-store-app-farm-steal-your-money/">series</a> of <a href="http://thenextweb.com/apple/2010/07/04/appstore-hack-itunes/">articles</a> that detail how corrupt app developers have been using what they describe as &#8220;app farms&#8221; to hack into users accounts and purchase their own apps.  Since originally posting the article, the first developer mentioned, &#8220;Thuat Nguyen,&#8221; has been removed from the app store, but The Next Web is reporting several other suspiciously successful developers who may be running the same kind of scam.  Several users are reporting unauthorized iTunes purchases in the comments.</p>
<p>[inline-ad align="right"]Alexandru Brie first reported on his blog how his app (Self Help Classics) had lost its position in the top 20 in the books category to a group of &#8220;badly coded Vietnamese manga apps.&#8221; All but one without reviews, and all by the same developer, Thuat Nguyen.  After being in touch with the app store team, and hearing from Phil Schiller himself that Apple was looking into the problem, Alexandru <a href="http://www.alexbrie.com/archives/215">posted an update</a> to his original story that highlighted several other suspicious developers in the top 200 apps in the books category.</p>
<p>In contrast, Arnold Kim <a href="http://www.macrumors.com/2010/07/04/reports-of-app-store-hacked-greatly-exaggerated/">wrote on MacRumors</a> that the issue of hacked iTunes accounts is not new, and points to a <a href="http://forums.macrumors.com/showthread.php?t=407990&amp;highlight=itunes+hacked">running thread</a> they&#8217;ve had open since January 2008.  Kim notes that the Books category is one of the smallest, representing a tiny amount of sales compared to the millions of iTunes accounts.</p>
<p>Right now, there are a lot of unknowns, and some good reasons to be suspicious of how widespread the problem really is.  We don&#8217;t know if the code of the app store has truly been hacked, or if the crooked developers have been using password guessing and targeting users with weak passwords.  If the app store really has been &#8220;hacked,&#8221; then the strength of your password won&#8217;t matter, but I think this is unlikely.  A brute force password-guessing attack goes after the weakest link: the users.</p>
<p>No matter how widespread the problem is, Apple should be taking it seriously.  It is apparent that there are still holes in the curated &#8220;<a href="http://mrgan.tumblr.com/post/653708588/the-walled-garden">walled garden</a>&#8221; and that the overall problem of the app store, the <a href="http://theappleblog.com/2008/09/13/why-apples-app-store-approval-process-is-broken/">approval process</a>, is still broken.  How can these crooked, worthless apps get in, when some <a href="http://daringfireball.net/search?q=rejection+of+the+week">truly useful apps</a> do not?</p>
<p>Post in the comments if you&#8217;ve seen any unauthorized charges on your iTunes account.</p>
<br />  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=174367&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" /><p><a href="http://pubads.g.doubleclick.net/gampad/jump?iu=/1008864/GigaOM_RSS_300x250&#038;sz=300x250&#038;c=943304"><img src="http://pubads.g.doubleclick.net/gampad/ad?iu=/1008864/GigaOM_RSS_300x250&#038;sz=300x250&#038;c=943304" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/2010/07/05/holes-in-the-walled-garden-has-the-app-store-been-hacked/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:thumbnail url="http://gigapple.files.wordpress.com/2010/07/app_store_icon_thumb.png?w=150" />
		<media:content url="http://gigapple.files.wordpress.com/2010/07/app_store_icon_thumb.png?w=150" medium="image">
			<media:title type="html">app_store_icon_thumb</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/7d5b8247e2eb580f5443ade7bbf2a067?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">jBuys</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2009/04/app_store_icon.png" medium="image">
			<media:title type="html">app_store_icon</media:title>
		</media:content>
	</item>
		<item>
		<title>AOL&#039;s Third Screen Media Hacked, Served Up Spam</title>
		<link>http://gigaom.com/2008/06/08/aol-third-screen-media-spam/</link>
		<comments>http://gigaom.com/2008/06/08/aol-third-screen-media-spam/#comments</comments>
		<pubDate>Sun, 08 Jun 2008 13:47:41 +0000</pubDate>
		<dc:creator>Om Malik</dc:creator>
				<category><![CDATA[Web]]></category>
		<category><![CDATA[AOL]]></category>
		<category><![CDATA[Hacked]]></category>
		<category><![CDATA[Platform-A]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[T Boone Pickens]]></category>
		<category><![CDATA[Third Screen Media]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://gigaom.com/?p=13708</guid>
		<description><![CDATA[Update: Platform-A&#8217;s official statement on the breach. Original Story below the fold. Platform-A has determined that the servers that host Third Screen Media’s corporate web site were breached during the weekend of June 6-8, 2008. The breach resulted in malicious code and web pages being loaded [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=140613&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><strong>Update:  Platform-A&#8217;s official statement on the breach. Original Story below the fold.</strong></p>
<blockquote><p>Platform-A has determined that the servers that host Third Screen Media’s corporate web site were breached during the weekend of June 6-8, 2008.  The breach resulted in malicious code and web pages being loaded on the web server. Third Screen Media’s web site is supported by a third-party hosting provider, which is completely separate from its production ad-serving systems.  We have confirmed that the company’s advertising systems have not been impacted and remain secure.</p>
<p>The site has been taken down and all malicious content has been removed.  Platform-A&#8217;s technical staff is investigating the breach to determine the appropriate changes necessary to secure the systems.  Once the appropriate changes have been made, the site will be made operational again.</p></blockquote>
<p><span id="more-140613"></span>Jeff Bentley, a reader of our site accidentally <a href="http://www.lifeinsearch.com/2008/06/06/getting-high-with-advertisingcom/">stumbled into what seems like a hack </a>by spammers of Third Screen Media, a mobile advertising company that was acquired by AOL in 2007 for $107  million and is <a href="http://gigaom.com/2008/03/26/platform-a-in-its-first-semester-a-failing-grade/">now part of Platform A.</a></p>
<p><img  title="3rdscreenspam" src="http:///2008/06/3rdscreenspam.gif" alt="" width="325" height="234" class=" alignleft" />While surfing on his Blackberry browser, Bentley found that somehow one his sites had been hacked and there were some spammy links embedded in the header of the pages on that site. All the links were emerging out of Third Screen Media&#8217;s domain and were pages built for pharmaceuticals related spam. Essentially Third Screen is serving as a spam-farm for someone. We have written in the past about <a href="http://gigaom.com/2007/11/26/wordpress-themes-security-problems/">how WordPress themes are being used</a> to embed spam links and other nefarious stuff. <em>(He has links to everything on his blog.)</em></p>
<p>Anyway this brings up the question: how secure is Platform A&#8217;s ThirdScreenMedia? Or is it someone from within who is mucking around and using the company&#8217;s domain to serve up spam. Blame it on the gorgeous blue skies this morning, but I am having a hard time thinking that ThirdScreen themselves could be to blame and offering spam-links as a service ;-).</p>
<p>PS: I will update the post after I hear back from Platform A.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/gigaom2.wordpress.com/140613/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/gigaom2.wordpress.com/140613/" /> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=140613&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" /><p><a href="http://pubads.g.doubleclick.net/gampad/jump?iu=/1008864/GigaOM_RSS_300x250&#038;sz=300x250&#038;c=134707"><img src="http://pubads.g.doubleclick.net/gampad/ad?iu=/1008864/GigaOM_RSS_300x250&#038;sz=300x250&#038;c=134707" /></a></p><p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=tech&utm_medium=editorial&utm_campaign=auto3&utm_term=140613+aol-third-screen-media-spam&utm_content=om">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2012/01/12-tech-leaders-resolutions-for-2012/?utm_source=tech&utm_medium=editorial&utm_campaign=auto3&utm_term=140613+aol-third-screen-media-spam&utm_content=om">12 tech leaders’ resolutions for 2012</a></li><li><a href="http://pro.gigaom.com/2012/10/the-state-of-cross-platform-measurement-across-tv-online-and-social/?utm_source=tech&utm_medium=editorial&utm_campaign=auto3&utm_term=140613+aol-third-screen-media-spam&utm_content=om">The state of cross-platform media measurement</a></li><li><a href="http://pro.gigaom.com/2012/10/social-third-quarter-2012-analysis-and-outlook/?utm_source=tech&utm_medium=editorial&utm_campaign=auto3&utm_term=140613+aol-third-screen-media-spam&utm_content=om">Social third-quarter 2012: analysis and outlook</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/2008/06/08/aol-third-screen-media-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/89c6ff98059617751fcf312690965fa0?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">om</media:title>
		</media:content>

		<media:content url="http:///2008/06/3rdscreenspam.gif" medium="image">
			<media:title type="html">3rdscreenspam</media:title>
		</media:content>
	</item>
	</channel>
</rss>