PSA: LJ Security Breach

Sep 23, 2009 09:00

Fortunately I seem to have escaped, but at least one person on my flist was just complaining about this, and it seems to be a pretty widespread problem: the lj-toys.com domain is causing a security breach in LJ. That post has some good tips on what to do if this has happened to you (or if you don't want it to happen to you), as does this post by 50mm. Among the more alarming things going on here is that it's resetting recent entries to public. Well, that, and it's spreading malware around the internets, which is also bad.

I've taken the precaution of checking my most recent entries for malicious embeds that I didn't put there (go to "edit entry" and look for funky html, then delete it), blocking lj-toys.com with AdBlock (a Firefox add-on that I already use), and switching to placeholders for embedded vids.

As I said, I haven't had my entries hijacked, but I have noticed, of late, my flist occasionally taking a long time to reload, even on a fast connection, and the culprit, according to the little taskbar at the bottom of Firefox, is usually lj-toys. Which I don't even use myself. So I'm just as glad, I suppose, to have been given the instigation to block it (which I should probably have already done, if it was causing things to load slowly).

ETA: Update from LJ. Allegedly things are now under control again.
Previous post Next post
Up