Affichage des articles dont le libellé est Another Day. Afficher tous les articles
Affichage des articles dont le libellé est Another Day. Afficher tous les articles

mercredi 8 juin 2016

Another Day, Another Hack: User Accounts for BitTorrent's Forum

Hackers have obtained tens of thousands of user accounts for the forum of popular data trading software BitTorrent.

Security researcher Troy Hunt got hold of the dataset and uploaded it to his data breach notification site Have I Been Pwned on Wednesday. Motherboard also obtained the data and verified its contents.

The dump contains just over 34,000 usernames, email addresses, IP addresses, and salted SHA1 password hashes. A “salt” is a random variable added to a hashing algorithm, which should make the passwords harder for hackers to crack.

Hunt pointed out that the forum is based on IP.Board, a piece of software that has led to several other data breaches.

“We can confirm that there was a security issue involving the vendor which powers our forums,” Christian Averill, a spokesperson for BitTorrent, told Motherboard in an email. “The vulnerability appears to have been through one of the vendor’s other clients, however it allowed attackers to access some information on other accounts, such as ours.”

“As a result, attackers were able to download a list of our forum users. We are investigating further to learn if any other information was accessed,” Averill continued.

BitTorrent also advised its users to change their passwords, especially if the same password was used on multiple sites.

Strangely, Averill added, “Our vendor has made backend changes so that the hashes in the file do not appear to be a usable attack vector.”

It’s not totally clear what BitTorrent means by this. It could mean they’ve invalidated affected accounts on the site so user passwords will no longer work.

It could also mean that the password hashing algorithm has since been changed on the site, but that doesn’t stop hackers from cracking the hashes they've already got and obtaining users' passwords. BitTorrent did not provide clarification in time for publication.

“This just adds to the troves and troves of data we've seen leaked in recent times,” Hunt told Motherboard in an email. “It also follows a similar pattern to many previous data breaches; a PHP-based forum storing passwords in a weak fashion and being leaked without the site owner even realising it.”

The lesson: Although people often focus on passwords in a dump, the leak of other information such as IP addresses poses its own risks. Although it may not be immediately obvious, a hacker could use this information for phishing scams, or just to get a much better idea of where a user is located.

For that reason, you might consider using a virtual private network (VPN) when using the internet. That way, if a site is hacked and your IP address leaked, hackers will only have access to the address of the server you routed your traffic through.

Read previous installments of Another Day, Another Hack here.

Another Day, Another Hack: User Accounts for BitTorrent's Forum

dimanche 5 juin 2016

Another Day, Another Hack: 100 Million Accounts for VK, Russia's Facebook

Accounts for over 100 million users of popular social media site VK.com are being traded on the digital underground.

Breach notification site LeakedSource obtained the data and published an analysis on Sunday. The hacker known as Peace, meanwhile, listed the data for sale on a dark web marketplace.

VK, heavily inspired by Facebook, is particularly popular in Russia, and has all the same features one might expect, including messaging, profiles, photo galleries, like buttons, and more. The site was founded by Pavel Durov, who sold his stake in VK and created the messaging app Telegram. As of 2014 VK had 100 million users, according to TechCrunch.

Peace provided Motherboard with a dataset containing a total of 100,544,934 records, and LeakedSource provided a smaller sample for verification purposes. The data contains first and last names, email address, phone numbers and passwords.

According to Peace, the passwords were already in plain text when the site was hacked, and were not cracked at a later date. Peace is selling the data for 1 bitcoin, or around $570 at today's exchange rates.

A screenshot of the listing on The Real Deal marketplace, a dark web site specialising in stolen data and computer exploits.

Out of 100 randomly selected email addresses from the larger dataset, 92 corresponded to active accounts on the site, Motherboard found. A Russian friend contacted by Motherboard confirmed that the password was correct.

While many of phone numbers were genuine, not all of users had numbers listed. At the time of writing, a phone number is required upon registration, but that was not always the case.

Indeed, according to Peace, the site was hacked sometime between 2011 and 2013, although exactly when is unclear. Peace claimed to have access to another 71 million accounts, but decided not to sell them yet.

LeakedSource wrote on its blog that the data was provided by someone who used the alias “Tessa88.” This is the same pseudonym that came up around the recent proliferation of user data from MySpace.

According to LeakedSource's analysis, the most popular password in the dataset was “123456,” with 709,067 appearances. Many other passwords were predictable, including “qwerty,” “123123,” and “qwertyuiop.”

The vast majority of email addresses, according to LeakedSource, use the “@mail.ru” domain, with 41,132,524. Other Russian services dominate the list of top email domains.

Neither Durov from Telegram or the press contact for VK replied to a request for comment.

The lesson: Huge datadumps of email addresses and passwords continue to surface. Again, the main lesson from all of these hacks is that users have to create a unique password for every site. This shouldn't be seen as a fancy, additional security step, but a fundamental one to stop hackers getting into different accounts. When the most popular sites on the internet, and the ones that hold our most personal information, are being breached, proper password use is a must.

Another Day, Another Hack: 100 Million Accounts for VK, Russia's Facebook

jeudi 2 juin 2016

Another Day, Another Hack: User Accounts of Dating Site Badoo

User accounts for dating site Badoo are being traded in the digital underground, including email address, cracked passwords, names, and dates of birth.

Paid subscription-based breach monitoring site 'Leaked Source' uploaded the dataset on Thursday. Other sources known to Motherboard have also obtained the data.

“With over 313m users, Badoo is great for chatting, making friends, sharing interests, and even dating!” reads Badoo's website.

Leaked Source provided three chunks of data to Motherboard, each containing 10,000 records. Out of 100 accounts tested across the three samples, 54 were linked to an active account on Badoo, while 23 indicated that an account had been created, but that the user had not completed registration by clicking the confirmation link emailed to them.

Messages sent to many of the email addresses linked to accounts on Badoo did not successfully deliver. Motherboard is yet to hear back from any of the apparent victims, and we will update this article if we receive a response.

In all, the data dump apparently contains 127,343,437 records. Motherboard was unable to confirm whether the dump was indeed this large, but another source who also obtained the data reported a similar figure.

Passwords in the samples provided to Motherboard were hashed with MD5, a hashing algorithm that has long been trivial for hackers to crack. According to Leaked Source, nearly 50,000 of the passwords in the datadump were “badoo”. No one Motherboard spoke to who was in possession of the dump knew exactly when the data was hacked.

For its part, Badoo denied being the source of the stolen accounts.

“Badoo takes privacy and security extremely seriously. Badoo has not been hacked and our user records/accounts are secure. We monitor our security constantly, and take extreme measures to protect our user base. We were made aware of an alleged data breach, which upon a thorough investigation into our system, we can confirm did not take place,” Badoo spokesperson Joelle Hadfield told Motherboard in an email.

That statement is near identical to another issued recently. In May, hackers claimed to have obtained over 50 million records from another dating site called Zoosk. As Motherboard and tech news site ZDNet found, that data was, however, likely not sourced from Zoosk. ZDNet approached Badoo when many of the supposed 'Zoosk' email addresses had the domain “@mobile.badoo.com.”

Curiously, 28,685,533 unique email addresses in the 'Zoosk' data also appeared in the Badoo data dump, according to Leaked Source. The exact connection between the two datasets is not clear at this stage, nor if they overlap in any other ways.

Regardless, details on Badoo users are being actively traded, and perhaps more than was previously known.

The lesson: As we've seen over the past week, sometimes data breaches take years to come to light. Users can't rely on waiting for a hack to go public, or for a company to acknowledge it. With that in mind, users should be thinking proactively, and taking steps to protect all their online accounts, even if one site they use does happen to be breached. One way of doing that is with a password manager, which generates strong, unique passwords and stores them either locally or online. That way, when one site is attacked, any details leaked won't necessarily allow hackers to access any other accounts.

Read previous installments of Another Day, Another Hack here.

Another Day, Another Hack: User Accounts of Dating Site Badoo

lundi 23 mai 2016

Another Day, Another Hack: Furry Site Hacked, Content Deleted

Quite literally, every day someone gets hacked. Whether that's a telecommunications company having its customer data stolen, or another chain of businesses being ripped for all the credit cards it processes, today one hack just seems to melt into another.

In our series Another Day, Another Hack, we do short posts giving you what you need to know about the hack, so you can figure out whether your bank account, website logins or anything else might be at risk. Because, even if the hack might not be the most sophisticated, real people are still getting fucked over somewhere, and should know about it.


Last week, a community of furries—people with an interest in anthropomorphic animal characters such as wolves and foxes—witnessed a popular online hub disappearing. Content including art submissions and user profiles on enthusiast site “Fur Affinity” was wiped, and hackers may have run off with email addresses and hashed passwords.

“We have just learned the attackers have access to personal user data, such as encrypted passwords and email addresses,” the site’s self-described Director of Operations, known as “Chase,” wrote last Friday on the Fur Affinity forums. Around Monday morning, a user called Fender announced that site passwords had been reset.

The Fur Affinity Twitter account has some 41,000 followers, and describes the site as “The world’s largest community of furries, anthros, dragons and more!” Fur Affinity, essentially an online gallery, allows users to upload music, writing, and art.

According to Fender, the problems started at the beginning of May, when researchers disclosed a vulnerability in the ImageMagick library that allows attackers to execute arbitrary code on websites. In this case, hackers downloaded Fur Affinity's source code before the administrators had patched the site.

Over a week later, Fur Affinity heard that people at an unnamed convention were handing out USB sticks containing that source code. The same day, the site was attacked again, and this time hackers deleted content. They were stopped before things such as journals and notes could be wiped, an administrator who calls themselves Dragoneer wrote last week on the Fur Affinity forums.

“While we were investigating [the USB sticks], somebody launched a second attack against the site using information gleaned from the source code,” Dragoneer said.

Fender wrote that, “At this time we do not know who executed the attacks on this site. An analysis of the attack vector used suggests these individual(s) were experienced attackers and not casual bystanders.” (However, the researchers who discovered the ImageMagick vulnerability said that the “exploit is trivial.”)

Fur Affinity has been restored from a May 11 backup, so the damage isn't too bad, and site passwords are supposedly hashed and salted. This means they might not be immediately cracked, though that is still possible.

The lesson: Even if a site, organisation or company says that no passwords have been stolen in an attack, you should reset yours anyway, especially if you used the same password on multiple services.

Another Day, Another Hack: Furry Site Hacked, Content Deleted

mercredi 18 mai 2016

Another Day, Another Hack: 117 Million LinkedIn Emails And Passwords

Quite literally, every day someone gets hacked. Whether that's a telecommunications company having its customer data stolen, or another chain of businesses being ripped for all the credit cards it processes, today one hack just seems to melt into another.

In our series Another Day, Another Hack, we do short posts giving you what you need to know about the hack, so you can figure out whether your bank account, website logins or anything else might be at risk. Because, even if the hack might not be the most sophisticated, real people are still getting fucked over somewhere, and should know about it.


A hacker is trying to sell the account information, including emails and passwords, of 117 million LinkedIn users.

The hacker, who goes by the name “Peace,” told Motherboard that the data was stolen during the LinkedIn breach of 2012. At the time, only around 6.5 million encrypted passwords were posted online, and LinkedIn never clarified how many users were affected by that breach.

Turns out it was much worse than anybody thought.

Peace is selling the data on the dark web illegal marketplace The Real Deal for 5 bitcoin (around $2,200). The paid hacked data search engine LeakedSource also claims to have obtained the data. Both Peace and the one of the people behind LeakedSource said that there are 167 million accounts in the hacked database. Of those, around 117 million have both emails and encrypted passwords.

“It is only coming to the surface now. People may not have taken it very seriously back then as it was not spread,” one of the people behind LeakedSource told me. “To my knowledge the database was kept within a small group of Russians.”

A screenshot of the listing on The Real Deal

LeakedSource provided Motherboard with a sample of almost one million credentials, which included email addresses, hashed passwords, and the corresponding hacked passwords. The passwords were originally encrypted or hashed with the SHA1 algorithm, with no “salt,” which is a series of random digits attached to the end of hashes to make them harder to be cracked.

One of the operators of LeakedSource told Motherboard in an online chat that so far they have cracked “90% of the passwords in 72 hours.”

Troy Hunt, a security researcher who maintains the breach notification siteHave I Been Pwned?,” reached out to some of the victims of the data breach. Two of them confirmed to Hunt that they indeed were users of LinkedIn and that the password he shared with them was the one they were using at the time of the breach. Motherboard was able to confirm a third victim.

One of the victims told Motherboard that the password in the sample was their current one, though he changed it as soon as Hunt reached out no notify him of the breach.

“Having a password out there feels like someone being able to let themselves in to your private space whenever they like, without you knowing,” the victim, who asked to remain anonymous, said in an email.

When reached for comment on Tuesday, LinkedIn spokesperson Hani Durzy told Motherboard that the company’s security team was looking into the incident, but that at the time they couldn’t confirm whether the data was legitimate. Durzy, however, also admitted that the 6.5 million hashes that were posted online in 2012 were not necessarily all of the passwords stolen.

“We don’t know how much was taken,” Durzy told me in a phone call.

The lesson: For LinkedIn, the lesson is the same as four years ago: don’t store password in an insecure way. As for LinkedIn users, if you didn’t already change your password four years ago, change it again, especially if you use it on other services (and please stop reusing passwords).

“The prevalence of password reuse means we’ll see that unlock other accounts too,” Hunt told me.

Another lesson is that even old hacked data can sometimes be valuable, given that some of these passwords might still be valid.


Another Day, Another Hack: 117 Million LinkedIn Emails And Passwords

mardi 10 mai 2016

Another Day, Another Hack: Is Your Fisting Site Updating Its Forum Software?

Quite literally, every day someone gets hacked. Whether that's a telecommunications company having its customer data stolen, or another chain of businesses being ripped for all the credit cards it processes, today one hack just seems to melt into another.

In our series Another Day, Another Hack, we do short posts giving you what you need to know about the hack, so you can figure out whether your bank account, website logins or anything else might be at risk. Because, even if the hack might not be the most sophisticated, real people are still getting fucked over somewhere, and should know about it.


A hacker has obtained over 100,000 user accounts for Rosebuttboard.com, a forum focused around “extreme anal dilation and anal fisting,” according to security researcher Troy Hunt.

The site is running years-old, out-of-date forum software that has known security vulnerabilities.

“This is a poignant reminder of how very personal information such as sexual proclivities may one day become public knowledge,” Hunt, who maintains the breach notification site 'Have I Been Pwned?', told Motherboard in an email. Hunt will be uploading the data to his site, so potential victims can check whether their data has been exposed.

Out-of-date software is arguably an indicator for how seriously a site takes security

Hunt obtained the data, which includes usernames, email addresses, IP addresses, and passwords hashed with the notoriously weak MD5 algorithm, along with a salt for some 107,303 accounts, and verified its authenticity.

A hashing algorithm takes a password and outputs a seemingly garbled up version of it, known as a hash, and a salt is another variable added to the password, designed to make the hash even harder to crack.

Motherboard has not seen the dataset, so has not been able to independently verify it.

Rosebuttboard.com describes itself as the “top one board for anal fisting, prolapse, huge insertion and rosebutt fans.”

As pointed out by Hunt, Rosebuttboard is running on version 3.4.6 of IP.Board, a piece of PHP-based software for creating forums, which uses MySQL databases. Vulnerabilities for this version include a cross-site scripting vulnerability, which would allow an attacker to execute arbitrary code; another that leads to full path disclosure, and an SQLi vulnerability, which may give the potential for an attacker to obtain user data.

It is unclear however whether any of these vulnerabilities or others in IP.Board led to the Rosebuttboard.com user accounts being hacked (administrators of the site did not respond to a request for comment). But out-of-date software is arguably an indicator for how seriously a site takes security, and especially one that deals with as sensitive a subject as sexual desires and fetishes.

The lesson: When it comes to website security, users are largely at the whim of site administrators, especially when it comes to the constant updating of software. For that reason, perhaps users of more sensitive sites should consider signing up with a pseudonymous email address, so when their data does become public, at least they are still protected somewhat.


Image: Che Saitta-Zelterman

Another Day, Another Hack: Is Your Fisting Site Updating Its Forum Software?

jeudi 5 mai 2016

Another Day, Another Hack: Tens of Millions of Neopets Accounts

Quite literally, every day someone gets hacked. Whether that's a telecommunications company having its customer data stolen, or another chain of businesses being ripped for all the credit cards it processes, today one hack just seems to melt into another.

In our series Another Day, Another Hack, we do short posts giving you what you need to know about the hack, so you can figure out whether your bank account, website logins or anything else might be at risk. Because, even if the hack might not be the most sophisticated, real people are still getting fucked over somewhere, and should know about it.

Tens of millions of user accounts from virtual pets community Neopets have allegedly been hacked and traded on the criminal underground.

Neopets, owned by games company JumpStart, is a website that allows players to care for digital “pets,” and buy items for them with virtual currency. Users signup with an email address, and provide a limited amount of personal information, such as their gender, country, state, and date of birth.

Motherboard obtained a sample of 100,000 apparent Neopet user accounts. Out of 100 randomly selected usernames, 83 corresponded to ones on Neopets. No apparent victims included in the Neopets breach responded to requests for comment, although the emails did deliver successfully.

Not all of the records contained every piece of information. For example, some accounts did not seem to include an email address. Why this was the case is unclear.

“After investigating the sample dataset of 100,000 records you forwarded, we have determined that the dataset was dated several years ago, prior to our Neopets acquisition,” Jim Czulewicz, chief revenue officer for JumpStart told Motherboard in an emailed statement. JumpStart acquired Neopets in 2014.

“Regardless, Neopets and our customers were the victim of a cyberattack and likely criminal activity. We plan to notify all users about the incident and advise them to reset their password. The security of our users' personal information has always been a top priority for our company,” Czulewicz continued.

“It is important to note that no credit card or physical address information was included in the dataset and Neopets does not store any customer credit card or other payment information, so that specific data is not at risk of ever being compromised. Our brand is about creating joy and entertainment in the lives of our users and we are committed to always ensuring that experience is delivered in a secure, safe environment,” he added.

The number of records hacked allegedly totaled over 70 million, but Motherboard was unable to confirm this. At the time of writing, Neopets has in excess of 90 million users.

This isn't the first time hackers have seemingly gone after Neopets. According to a September 2015 report, hackers planned to release records on every user of the site. It is not totally clear whether that breach, and this latest data set, are connected.

The lesson: As Czulewicz recommended, any Neopets users, even if they no longer play on the site, should change their password. With the information in the dump, a hacker could potentially access other services if they are protected with the same password.

Another Day, Another Hack: Tens of Millions of Neopets Accounts