{"id":7622,"date":"2013-07-24T13:48:10","date_gmt":"2013-07-24T17:48:10","guid":{"rendered":"http:\/\/mjtsai.com\/blog\/?p=7622"},"modified":"2022-04-14T14:45:06","modified_gmt":"2022-04-14T18:45:06","slug":"developer-center-downtime","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2013\/07\/24\/developer-center-downtime\/","title":{"rendered":"Developer Center Downtime"},"content":{"rendered":"<p><a href=\"http:\/\/devimages.apple.com\/maintenance\/\">Apple<\/a>:<\/p>\n<blockquote cite=\"http:\/\/devimages.apple.com\/maintenance\/\"><p>Last Thursday, an intruder attempted to secure personal information of our registered developers from our developer website. Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers&rsquo; names, mailing addresses, and\/or email addresses may have been accessed. In the spirit of transparency, we want to inform you of the issue. We took the site down immediately on Thursday and have been working around the clock since then.<\/p><\/blockquote>\n<p><a href=\"http:\/\/www.imore.com\/closer-look-possible-cause-apples-developer-portal-outage\">Nick Arnott<\/a> interviews Ibrahim Balic:<\/p>\n<blockquote cite=\"http:\/\/www.imore.com\/closer-look-possible-cause-apples-developer-portal-outage\"><p>With altered web requests, Balic found that by only providing a single piece of user information, first name, last name, etc., he was able to get Apple&rsquo;s servers to return additional information for a matched user account &mdash; specifically full name, username and email address.<\/p>\n<p>[&#8230;]<\/p>\n<p>So if the bug was in iAd, why does Balic believe he might be responsible for the developer portal outage? Of the 13 bugs that Balic filed with Apple, one of them was a XSS (cross-site scripting) vulnerability in the developer site that could have led to accounts being compromised. In fact, of the 13 total bugs, 12 of them were XSS vulnerabilities in various Apple services that had the potential to expose user details. <\/p>\n<\/blockquote>\n<p>Update (2013-07-24): They&rsquo;ve added a system <a href=\"https:\/\/developer.apple.com\/support\/system-status\/\">status page<\/a>.<\/p>\n<p>Update (2013-07-28): Sites are reporting that the ADC Web site is back up, although the status page shows that Xcode Automatic Configuration (presumably necessary to install the command-line tools), Pre-Release Documentation, Videos, Member Center, App Store Resource Center, Program Enrollment and Renewals, Apple Developer Forums, and Technical Support are all still down.<\/p>\n<p>Update (2013-08-10): All the services are <a href=\"http:\/\/tidbits.com\/e\/14008\">back online<\/a>.<\/p>\n<p>Update (2013-08-21): <a href=\"http:\/\/www.macrumors.com\/2013\/08\/20\/apple-developer-center-outage-fixed-remote-code-execution-flaw\/\">Juli Clover<\/a> (via <a href=\"http:\/\/daringfireball.net\/linked\/2013\/08\/20\/adc-outage\">John Gruber<\/a>):<\/p>\n<blockquote cite=\"http:\/\/www.macrumors.com\/2013\/08\/20\/apple-developer-center-outage-fixed-remote-code-execution-flaw\/\">\n<p>Apple has released new details (<a href=\"https:\/\/twitter.com\/cabel\/status\/369562221820387328\">via @cabel<\/a>) on the security flaw that caused the Developer Center to be down for more than a week, noting via its <a href=\"http:\/\/support.apple.com\/kb\/HT1318?viewlocale=en_US&amp;locale=en_US\">Apple Web Server notifications page<\/a> that a &ldquo;remote code execution issue&rdquo; was fixed.<\/p>\n<p>[&#8230;]<\/p>\n<p>While security researcher Ibrahim Balic <a href=\"http:\/\/www.macrumors.com\/2013\/07\/22\/researcher-takes-credit-for-security-breach-of-apples-developer-center\/\">speculated<\/a> that he might have been behind the <a href=\"http:\/\/www.macrumors.com\/2013\/07\/21\/apple-developer-website-hacked-developer-names-addresses-may-have-been-taken\/\">security breach<\/a>, it is now clear that the issue he reported was unrelated to the major flaw that caused the downtime.<\/p><\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Apple: Last Thursday, an intruder attempted to secure personal information of our registered developers from our developer website. Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers&rsquo; names, mailing addresses, and\/or email addresses may have been accessed. In the spirit of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2022-04-14T18:45:08Z","apple_news_api_id":"dc937825-74b5-4e93-bbb3-ae264c7e3120","apple_news_api_modified_at":"2022-04-14T18:45:08Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/A3JN4JXS1TpO7s64mTH4xIA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[38,2190,48,96],"class_list":["post-7622","post","type-post","status-publish","format-standard","hentry","category-technology","tag-apple","tag-outage","tag-security","tag-web"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/7622","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=7622"}],"version-history":[{"count":6,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/7622\/revisions"}],"predecessor-version":[{"id":35570,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/7622\/revisions\/35570"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=7622"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=7622"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=7622"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}