Coding4Food LogoCoding4Food
HomeCategoriesArcadeBookmarks
vi
HomeCategoriesArcadeBookmarks
Coding4Food LogoCoding4Food
HomeCategoriesArcadeBookmarks
Privacy|Terms

© 2026 Coding4Food. Written by devs, for devs.

All news
IT DramaTechnology

Wikipedia Goes Read-Only: The Old-School XSS Worm That Nuked Admin Accounts

March 6, 20263 min read

Wikipedia was forced into read-only mode after a classic XSS worm compromised admin accounts. Let's unpack this dumpster fire of jQuery and PHP memes.

Share this post:
scam, alert, cybersecurity, phishing, fraud, hacker, crime, attack, warning, cut out, scam, scam, scam, scam, scam
Nguồn gốc: https://coding4food.com/post/wikipedia-read-only-mass-admin-xss-worm. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/wikipedia-read-only-mass-admin-xss-worm. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/wikipedia-read-only-mass-admin-xss-wormNguồn gốc: https://coding4food.com/post/wikipedia-read-only-mass-admin-xss-worm. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/wikipedia-read-only-mass-admin-xss-worm. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/wikipedia-read-only-mass-admin-xss-worm
Nguồn gốc: https://coding4food.com/post/wikipedia-read-only-mass-admin-xss-worm. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/wikipedia-read-only-mass-admin-xss-worm. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/wikipedia-read-only-mass-admin-xss-wormNguồn gốc: https://coding4food.com/post/wikipedia-read-only-mass-admin-xss-worm. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/wikipedia-read-only-mass-admin-xss-worm. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/wikipedia-read-only-mass-admin-xss-worm
xss wormwikipedia sậpbảo mậtmediawikibug xssdrama ithack tài khoảnjquery
Share this post:

Bình luận

Related posts

work, computer, apple, business, office, desk, technology, pen, phone, smartphone, workstation, blog, blogging, table, book, mouse, computer, apple, apple, apple, business, office, office, office, desk, blog, blog, blog, blog, blog, blogging, blogging, book
IT DramaTechnology

Lean Startup Godfather Eric Ries Drops Truth Bombs on Corporate Greed and Gets Roasted by AI Drama

Eric Ries returns to HN to promote his new book 'Incorruptible', introducing 'financial gravity' while getting roasted over his Claude Code generated site.

Jun 113 min read
Read more →
euro, europe, rocket, nature, prices, price increase, clouds, heaven, strip, aviator, finance, money, currency, inflation, economic crisis, energy crisis, energy saving, market economy, cost, development, stock exchange
TechnologyIT Drama

S&P 500 Slams the Door on SpaceX & AI Giants: Cash is King, Hype is Dead

The S&P 500 committee rejected SpaceX's fast-track and blocked unprofitable AI giants like OpenAI and Anthropic. Read the full drama and tech reactions here!

Jun 63 min read
Read more →
printed circuit board, circuit board, electronics, circuit, computer chip, microchip
IT DramaTechnology

PR Nightmare 101: Flux.ai Sends Legal Goons After Open-Source Darling Adafruit

VC-backed startup Flux.ai thought sending a legal demand letter to Adafruit was a big brain move. Spoiler alert: The internet is now roasting them alive.

Jun 32 min read
Read more →
robot, technology, universe, galaxy, system, robotic, matrix, code, programming, ai generated, coding, computer, hacker, binary, fantasy
IT DramaTechnology

The Goofiest Instagram Exploit: Hackers Sweet-Talked Meta's AI Bot into Handing Over Accounts

Meta got clowned by the silliest exploit in history. Hackers literally gaslit an AI support bot into transferring Instagram accounts without writing a single line of code.

Jun 22 min read
Read more →
code, coding, computer, data, developing, development, ethernet, html, programmer, programming, screen, software, technology, work, code, code, coding, coding, coding, coding, coding, computer, computer, computer, computer, data, programming, programming, programming, software, software, technology, technology, technology, technology
Dev LifeIT Drama

"LLMs Are Eating My Career" - A Dev's Existential Crisis on Hacker News

A trending Hacker News post reveals mid-career panic as devs feel LLMs are taking over. Are AI tools ending software engineering or just evolving it?

Jun 73 min read
Read more →
matrix, code, computer, pc, data, program, computer virus, programming, zoom background, coding, wallpaper, matrix, matrix, matrix, matrix, matrix, code, code, computer, computer, data, data, programming, coding, coding
TechnologyAI & Automation

Astra Autonomous Pentest: When AI Stops Drawing and Starts Hacking Your Server

Astra Security's AI pentest tool is making waves on Product Hunt. It finds, exploits, and fixes bugs autonomously. Are red teamers cooked?

Jun 53 min read
Read more →

Just when you thought XSS worms were a relic of the MySpace era, Wikipedia gets body-slammed by a piece of JavaScript hiding behind jQuery. Imagine trying to look up some obscure software engineering concept, only to be greeted by a glaring red "Read-only mode" banner.

Yep, Wikimedia Foundation had to lock down the entire internet's encyclopedia because a bunch of admin accounts got massively compromised. Let's unpack this glorious dumpster fire.

What in the MySpace Samy is going on here?

For those who missed the chaotic status updates, Wikipedia basically had to revoke write access for everyone. The culprit? An old-school Cross-Site Scripting (XSS) worm.

The payload somehow managed to inject itself into the global MediaWiki:Common.js page (and User:Common.js as a fallback). Once a user loaded the infected script, it executed a wild sequence of events:

  • Stealth mode via jQuery: It literally uses jQuery to hide UI elements so the victim doesn't realize their account is acting up. (Shoutout to jQuery in 2024!).
  • Vandalism: It defaces about 20 random articles by injecting a massive 5000px-wide image.
  • The Nuke: If the infected user happens to be an Admin, the script triggers Special:Nuke to silently delete 3 random articles from the global namespace, plus another 20 using the action=delete endpoint.
  • The Signature: It leaves behind the Russian phrase "Закрываем проект" (Closing the project).

Hacker News & Reddit having a field day

The dev community's reaction has been a mix of pure nostalgia and cynical tech-bashing.

1. The "Script Kiddie" Theory Security sleuths quickly noticed the worm tried to load an additional XSS script from basemetrika.ru. The hilarious part? That domain doesn't even exist (NXDomain response). This sparked debates on whether it's a script kiddie who messed up their payload, or if the worm was hallucinated by an AI that just made up a fake URL.

2. The Missed Opportunity As one pragmatic dev pointed out: If you have a self-replicating XSS worm running in the browsers of Wikipedia admins, why just vandalize articles? They could have easily harvested credentials via browser autofill. A massive credential leak would be infinitely worse. Instead, the attacker chose chaos and 5000px images.

3. The Obligatory PHP Bashing It wouldn't be a MediaWiki drama without someone dragging PHP through the mud. One commenter summed it up perfectly: "Here before someone says that it's because MediaWiki is written in PHP - the language where 'return flase' causes it to return true."

4. Peak Wikipedia Humor Even locked-out editors couldn't resist a joke: "How do we know Wikipedia is down? Has this been published in a Reliable Source?"

The Takeaway: Trust No One

Jokes aside, there's a serious lesson here. MediaWiki has historically allowed high-level users to embed custom JS for UI tweaks. From a security standpoint, that's like handing out loaded shotguns at a party.

As developers, let this be your daily reminder: Never trust user input. It doesn't matter if they are a regular user, an Admin, or the CEO. Sanitize your inputs, implement strict Content Security Policies (CSP), and for the love of god, don't execute raw user-provided strings. Otherwise, you might be the one writing an incident report at 3 AM.


Sources:

  • Wikimedia Status: https://www.wikimediastatus.net
  • Hacker News Thread / Wikipediocracy / Reddit.