Hacker News new | ask | show | jobs
by hnysacct 3463 days ago
Well the PR got merged, and finally he responded to my original request via email:

"Im sorry I did not get back sooner as I and another family member have been unwell in bed most of the last week.

I'd like to you for spoiling my Christmas

Now, someone hacked the server and deleted the whole gitpay database.

This was just volunteer work, so that open source developers like myself who get no pay might be able to a tiny amount of donations.

I have now lost a huge amount of work.

I hope you feel quite satisfied."

1 comments

That sucks that he didn't have any backups, but it was just a matter of time before it happened. But nobody hacked the server; you can literally just throw SQL into the url: http://gitpay.org/user.php?user=%27%3B%20DROP%20DATABASE%20d.... That's why you should never trust any user input.