CodeChef
  • PRACTICE
    • Easy
    • Medium
    • Hard
    • Challenge
    • Peer
  • COMPETE
  • DISCUSS
    • Wiki
    • Forums
    • Blog
    • Twitter
  • COMMUNITY
    • CodeChef Meetups
    • Campus Chapters
    • Host Your Contest
    • User Groups
    • CodeChef TechTalks
  • HELP
    • Frequently Asked Questions
    • FAQ for Problem Setters
    • Ranks
    • Tutorials
  • ABOUT
    • About CodeChef
    • Team CodeChef
    • Press Room
    • CEO's Corner
    • About Directi

XSS attack! – We are back :)

Posted by Harsh on June 10th, 2011 Filed in Announcement 13 Comments »

Hey Guys,

As some of you may have noticed, there has been an xss attack on our site since yesterday. You may find that your profile data has been changed. We are trying to restore this. To prevent further problems we are taking the site down.

We apologize to our users for taking the site down in the middle of the contest. On a brighter note, this gives us an opportunity to make ourselves stronger. :)

We will be back soon.

UPDATE: We are back. We apologize for the prolonged downtime. We have tried our best to restore your data back and ensure that this does not occur again. However, we have not been able to update a few of your profiles, whom we request to update manually.

Please send a mail to feedback@codechef.com in case you still face any issues or suspect any malicious activity.

The contest will be extended to make up for the lost time.

Keep watching this space to know what actually transpired.

Regards,
Team CodeChef

Share
  • Dexter

    Oh Sad ! Good luck to the developers, Hope to see the site back again in action. 

    • radha krishnan

      Who attacked this website? 
      @CC admins : U find who did this XSS attack ? 

      • http://www.codechef.com CodeChef

        We believe that revealing the identity of the person does not do any good to anyone. We figured out who it was and have contacted the person who accepted.

  • Fringe

    Dexter is the hacker.

  • HIMYM

    Please Give Prior warning before taking the site off-line.
    I have a code written and I want to test it.
    And Increase the time-limit tomorrow.

    • http://www.codechef.com CodeChef

      It was taken off-line only to prevent the users’ data from being tampered. We are restoring back the data of as many users as we can. We will be back soon. Also the contest will be extended.

      • http://www.facebook.com/people/Suhash-Venkatesh/516736807 Suhash Venkatesh

         Good to hear that! It would be nice if you could specify the duration by which the contest has been extended! Thanks in advance!

      • Coolravi321

         you still did not tell what transpired.what happened?

        • Narayana

          I agree to CoolRavi.I think it is dangerous, because I also connect Facebook account to Codechef. If hacker get my auth token, he can steal my facebook info and give to malicious party. If Codechef cannot explain why XSS attack happen and if it can happen once more, I don’t think it is safe for me or any other programmer. It is bad that Codechef cannot find root of such bug. Please tell me how to delete account. I try hard to find, but not find any way of deleting Codechef.

          • http://www.codechef.com CodeChef

            There was a security loophole in the site that the hacker exploited to change the data of some users. The loophole allowed the hacker to attach Javascript code in the input fields on the profile page which when rendered was executed. It was a standard XSS attack and it is a bit of shame for us to harbor that loophole for so long on our website. We apologize for the inconvenience caused to you all. It has been fixed now and we can assure you all that your data is safe with us.

      • CoolRavi321

        I am asking because i am concerned for my security and data. is it safe to compete?

  • Pingback: June 2011 Challenge Winners! | Codechef

  • Bestwesternglendower

    We understand. There’s nothing to say sorry for. Just keep it up. Thanks.

    hotels st annes, lytham hotels, lytham st annes hotels, hotels in st annes, hotels in lytham  


Recent Posts

  • venuswitharms takes the sweet spot!
  • Another thrilling win for Gennady!!
  • Enjoy Faster Forums !!
  • AC Rushes to the top!
  • Roopantaran! (Facelift)

Categories

  • About (8)
  • ACM ICPC (5)
  • Announcement (78)
  • Campus Chapters (6)
  • College Contests (8)
  • Contests (111)
  • Events (20)
  • FAQ (1)
  • Features (30)
  • Meetup (4)
  • Open Source (1)
  • Practice Problems (7)
  • Prizes (16)
  • Problems (3)
  • Programmer of the Month (27)
  • Tech Talks (6)
  • Tutorials (13)
  • Winners (77)

Recent Comments

  • Anon on venuswitharms takes the sweet spot!
  • Hemesh Mnnit on AC Rushes to the top!
  • CodeChef on venuswitharms takes the sweet spot!
  • CodeChef on venuswitharms takes the sweet spot!
  • CodeChef on venuswitharms takes the sweet spot!

Recent Pictures

Blogroll

  • Documentation
  • Plugins
  • Suggest Ideas
  • Support Forum
  • Themes
  • WordPress Blog
  • WordPress Planet

Archives

  • May 2012
  • April 2012
  • March 2012
  • February 2012
  • January 2012
  • December 2011
  • November 2011
  • October 2011
  • September 2011
  • August 2011
  • July 2011
  • June 2011
  • May 2011
  • April 2011
  • March 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009

Company Blogs

  • Directi
  • .pw Corp Blog
  • CEOs Blog

Careers@Directi


  • About CodeChef
  • About Directi
  • CEO's Corner
  • CodeChef Campus Chapters
  • Blogger Community Program
  • User Group Outreach Program

© 2009, Directi Group. All Rights Reserved.

Sponsors