Feeds

FoxNews commentator Bill O'Reilly's website hacked

200 loyal followers Wikileaked

Build a business case: developing custom apps

Two days after someone broke into the email account of vice presidential candidate Sarah Palin, unknown intruders have hacked the website of conservative commentator Bill O'Reilly and posted personal details of more than 200 of its subscribers.

The breach into BillOreilly.com came as retaliation for remarks O'Reilly made on FoxNews condemning the attack on Palin's Yahoo email account, according to Wikileaks, a site that makes it easy for whistleblowers, hackers and anyone else to leak documents.

As proof, Wikileaks posted a screenshot of the BillOreilly.com administrative interface that showed the names, email addresses, passwords, and home town of 20 subscribers of the website. In all, information belonging to 205 subscribers was intercepted, according to Eric Marston, CTO of Nox Solutions, the company that maintained the O'Reilly website.

The hack came in response to comments O'Reilly made on Fox News about the posting of contents of Palin's email account, including pictures of her daughter and her contact list.

"I'm not going to mention the website that posted this, but it's one of those despicable, slimy, scummy websites," O'Reilly said, according to this snippet from YouTube. "Everybody knows where this stuff is, OK, and they know the people who run the website, so why can't they go there tonight to the guy's house who runs it, put him in cuffs and take him down and book him?"

It's evident from the remark that no one bothered to tell O'Reilly that Wikileaks, the first site to publish the Palin email, is a multi-national, bulletproof organization that has successfully withstood serious take-down efforts before. He's not the first conservative to have his lack of tech credentials in doubt. In July, Republican presidential candidate John McCain confessed he was still "learning to get online" and "becoming computer literate to the point where I can get the information that I need."

According to Marston, the hackers were able to access the unsecured list by trying a large number of variations of the website's administrative URL. He said all affected members have received an email and a phone call informing them of the breach and urging them to change their password anywhere they may have used it. No credit card information was stolen, and the site has since been completely locked down, Marston said.

BillOreilly.com charges $4.95 for monthly premium membership. The O'Reilly Store sells hats, mugs, T-shirts and other assorted schwag.

While the information exposed on Wikileaks may seem minimal, it has the potential to imperil the BillOreilly.com subscribers listed in ways they may not have anticipated. A case in point is Carolyn Carpenter, 68, of Henderson, Nevada. The list showed she used a six-letter word from the English language to access her account. Early Friday evening, when told she should change all accounts that used the password, she replied: "Oh damn, I use it all over the place." ®

(This story was updated to modify the headline; and to add details about McCain comments to the New York Times, about premium memberships on billoreilly.com, and about no credit card details being stolen.)

Endpoint data privacy in the cloud is easier than you think

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
Microsoft's Euro cloud darkens: US FEDS can dig into foreign servers
They're not emails, they're business records, says court
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Multipath TCP speeds up the internet so much that security breaks
Black Hat research says proposed protocol will bork network probes, flummox firewalls
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
Plug and PREY: Hackers reprogram USB drives to silently infect PCs
BadUSB instructs gadget chips to inject key-presses, redirect net traffic and more
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
prev story

Whitepapers

7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?