Oh no, you're thinking, yet another cookie pop-up. Well, sorry, it's the law. We measure how many people read us, and ensure you see relevant ads, by storing cookies on your device. If you're cool with that, hit “Accept all Cookies”. For more info and to customise your settings, hit “Customise Settings”.

Review and manage your consent

Here's an overview of our use of cookies, similar technologies and how to manage them. You can also change your choices at any time, by hitting the “Your Consent Options” link on the site's footer.

Manage Cookie Preferences
  • These cookies are strictly necessary so that you can navigate the site as normal and use all features. Without these cookies we cannot provide you with the service that you expect.

  • These cookies are used to make advertising messages more relevant to you. They perform functions like preventing the same ad from continuously reappearing, ensuring that ads are properly displayed for advertisers, and in some cases selecting advertisements that are based on your interests.

  • These cookies collect information in aggregate form to help us understand how our websites are being used. They allow us to count visits and traffic sources so that we can measure and improve the performance of our sites. If people say no to these cookies, we do not know how many people have visited and we cannot monitor performance.

See also our Cookie policy and Privacy policy.

HipChat SlipChat lets hackers RipChat

They're going to get plenty of LipChat


IRC-for-biz HipChat says a vulnerability in a software library used by its HipChat.com service allowed hackers to access private conversations and customer account information.

The ytalk-for-suits maker said on Monday an attacker was able to infiltrate a single server powering its cloud-hosted chat service, and, in the process, extracted account records – consisting of names, email addresses, and hashed passwords – and a number of chat logs and message exchanges.

The Atlassian-owned company said it hashed its passwords using bcrypt and a random salt, and has reset all of them just in case. The corp said it will notify all exposed users by email.

"As a precaution, we have invalidated passwords on all HipChat-connected user accounts and sent those users instructions on how to reset their passwords," said HipChat chief security officer Ganesh Krishnan.

"If you are a user of HipChat.com and do not receive an email from our Security Team with these instructions, we have found no evidence that you are affected by this incident."

While HipChat did not say exactly which programming blunder the attackers exploited to get into the HipChat cloud server, it did say "the incident involved a vulnerability in a popular third-party library used by HipChat.com."

"While HipChat Server uses the same third-party library, it is typically deployed in a way that minimizes the risk of this type of attack," said Krishnan. "We are preparing an update for HipChat Server that will be shared with customers directly through the standard update channel."

Last month, there was one third-party library used by Atlassian products in particular that received a major security fix: Struts 2, which was patched to erase a remote-code execution vulernability that was being exploited in the wild. Atlassian rated the flaw as "critical," and the bug was present in HipChat Server, the software you install to run your own HipChat service. Perhaps one of HipChat's cloud boxes running HipChat Server was pwned by miscreants exploiting Struts 2? We think so.

Krishnan reckoned "less than 0.05 per cent" of HipChat.com "messages and content in [chat] rooms may have been accessed," and that his team has found "no evidence of unauthorized access to financial and/or credit card information." ®

Similar topics


Other stories you might like

Biting the hand that feeds IT © 1998–2021