Feeds

FoxNews commentator Bill O'Reilly's website hacked

200 loyal followers Wikileaked

High performance access to file storage

Two days after someone broke into the email account of vice presidential candidate Sarah Palin, unknown intruders have hacked the website of conservative commentator Bill O'Reilly and posted personal details of more than 200 of its subscribers.

The breach into BillOreilly.com came as retaliation for remarks O'Reilly made on FoxNews condemning the attack on Palin's Yahoo email account, according to Wikileaks, a site that makes it easy for whistleblowers, hackers and anyone else to leak documents.

As proof, Wikileaks posted a screenshot of the BillOreilly.com administrative interface that showed the names, email addresses, passwords, and home town of 20 subscribers of the website. In all, information belonging to 205 subscribers was intercepted, according to Eric Marston, CTO of Nox Solutions, the company that maintained the O'Reilly website.

The hack came in response to comments O'Reilly made on Fox News about the posting of contents of Palin's email account, including pictures of her daughter and her contact list.

"I'm not going to mention the website that posted this, but it's one of those despicable, slimy, scummy websites," O'Reilly said, according to this snippet from YouTube. "Everybody knows where this stuff is, OK, and they know the people who run the website, so why can't they go there tonight to the guy's house who runs it, put him in cuffs and take him down and book him?"

It's evident from the remark that no one bothered to tell O'Reilly that Wikileaks, the first site to publish the Palin email, is a multi-national, bulletproof organization that has successfully withstood serious take-down efforts before. He's not the first conservative to have his lack of tech credentials in doubt. In July, Republican presidential candidate John McCain confessed he was still "learning to get online" and "becoming computer literate to the point where I can get the information that I need."

According to Marston, the hackers were able to access the unsecured list by trying a large number of variations of the website's administrative URL. He said all affected members have received an email and a phone call informing them of the breach and urging them to change their password anywhere they may have used it. No credit card information was stolen, and the site has since been completely locked down, Marston said.

BillOreilly.com charges $4.95 for monthly premium membership. The O'Reilly Store sells hats, mugs, T-shirts and other assorted schwag.

While the information exposed on Wikileaks may seem minimal, it has the potential to imperil the BillOreilly.com subscribers listed in ways they may not have anticipated. A case in point is Carolyn Carpenter, 68, of Henderson, Nevada. The list showed she used a six-letter word from the English language to access her account. Early Friday evening, when told she should change all accounts that used the password, she replied: "Oh damn, I use it all over the place." ®

(This story was updated to modify the headline; and to add details about McCain comments to the New York Times, about premium memberships on billoreilly.com, and about no credit card details being stolen.)

High performance access to file storage

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
NSA denies it knew about and USED Heartbleed encryption flaw for TWO YEARS
Agency forgets it exists to protect communications, not just spy on them
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.