Affichage des articles dont le libellé est Another Day. Afficher tous les articles
Affichage des articles dont le libellé est Another Day. Afficher tous les articles

Another Day, Another Hack: User Accounts for BitTorrent's Forum

mercredi 8 juin 2016

Hackers have obtained tens of thousands of user accounts for the forum of popular data trading software BitTorrent.

Security researcher Troy Hunt got hold of the dataset and uploaded it to his data breach notification site Have I Been Pwned on Wednesday. Motherboard also obtained the data and verified its contents.

The dump contains just over 34,000 usernames, email addresses, IP addresses, and salted SHA1 password hashes. A “salt” is a random variable added to a hashing algorithm, which should make the passwords harder for hackers to crack.

Hunt pointed out that the forum is based on IP.Board, a piece of software that has led to several other data breaches.

“We can confirm that there was a security issue involving the vendor which powers our forums,” Christian Averill, a spokesperson for BitTorrent, told Motherboard in an email. “The vulnerability appears to have been through one of the vendor’s other clients, however it allowed attackers to access some information on other accounts, such as ours.”

“As a result, attackers were able to download a list of our forum users. We are investigating further to learn if any other information was accessed,” Averill continued.

BitTorrent also advised its users to change their passwords, especially if the same password was used on multiple sites.

Strangely, Averill added, “Our vendor has made backend changes so that the hashes in the file do not appear to be a usable attack vector.”

It’s not totally clear what BitTorrent means by this. It could mean they’ve invalidated affected accounts on the site so user passwords will no longer work.

It could also mean that the password hashing algorithm has since been changed on the site, but that doesn’t stop hackers from cracking the hashes they've already got and obtaining users' passwords. BitTorrent did not provide clarification in time for publication.

“This just adds to the troves and troves of data we've seen leaked in recent times,” Hunt told Motherboard in an email. “It also follows a similar pattern to many previous data breaches; a PHP-based forum storing passwords in a weak fashion and being leaked without the site owner even realising it.”

The lesson: Although people often focus on passwords in a dump, the leak of other information such as IP addresses poses its own risks. Although it may not be immediately obvious, a hacker could use this information for phishing scams, or just to get a much better idea of where a user is located.

For that reason, you might consider using a virtual private network (VPN) when using the internet. That way, if a site is hacked and your IP address leaked, hackers will only have access to the address of the server you routed your traffic through.

Read previous installments of Another Day, Another Hack here.

Let's block ads! (Why?)

Another Day, Another Hack: User Accounts for BitTorrent's Forum

Another Day, Another Hack: 100 Million Accounts for VK, Russia's Facebook

dimanche 5 juin 2016

Accounts for over 100 million users of popular social media site VK.com are being traded on the digital underground.

Breach notification site LeakedSource obtained the data and published an analysis on Sunday. The hacker known as Peace, meanwhile, listed the data for sale on a dark web marketplace.

VK, heavily inspired by Facebook, is particularly popular in Russia, and has all the same features one might expect, including messaging, profiles, photo galleries, like buttons, and more. The site was founded by Pavel Durov, who sold his stake in VK and created the messaging app Telegram. As of 2014 VK had 100 million users, according to TechCrunch.

Peace provided Motherboard with a dataset containing a total of 100,544,934 records, and LeakedSource provided a smaller sample for verification purposes. The data contains first and last names, email address, phone numbers and passwords.

According to Peace, the passwords were already in plain text when the site was hacked, and were not cracked at a later date. Peace is selling the data for 1 bitcoin, or around $570 at today's exchange rates.

A screenshot of the listing on The Real Deal marketplace, a dark web site specialising in stolen data and computer exploits.

Out of 100 randomly selected email addresses from the larger dataset, 92 corresponded to active accounts on the site, Motherboard found. A Russian friend contacted by Motherboard confirmed that the password was correct.

While many of phone numbers were genuine, not all of users had numbers listed. At the time of writing, a phone number is required upon registration, but that was not always the case.

Indeed, according to Peace, the site was hacked sometime between 2011 and 2013, although exactly when is unclear. Peace claimed to have access to another 71 million accounts, but decided not to sell them yet.

LeakedSource wrote on its blog that the data was provided by someone who used the alias “Tessa88.” This is the same pseudonym that came up around the recent proliferation of user data from MySpace.

According to LeakedSource's analysis, the most popular password in the dataset was “123456,” with 709,067 appearances. Many other passwords were predictable, including “qwerty,” “123123,” and “qwertyuiop.”

The vast majority of email addresses, according to LeakedSource, use the “@mail.ru” domain, with 41,132,524. Other Russian services dominate the list of top email domains.

Neither Durov from Telegram or the press contact for VK replied to a request for comment.

The lesson: Huge datadumps of email addresses and passwords continue to surface. Again, the main lesson from all of these hacks is that users have to create a unique password for every site. This shouldn't be seen as a fancy, additional security step, but a fundamental one to stop hackers getting into different accounts. When the most popular sites on the internet, and the ones that hold our most personal information, are being breached, proper password use is a must.

Let's block ads! (Why?)

Another Day, Another Hack: 100 Million Accounts for VK, Russia's Facebook

Another Day, Another Hack: User Accounts of Dating Site Badoo

jeudi 2 juin 2016

User accounts for dating site Badoo are being traded in the digital underground, including email address, cracked passwords, names, and dates of birth.

Paid subscription-based breach monitoring site 'Leaked Source' uploaded the dataset on Thursday. Other sources known to Motherboard have also obtained the data.

“With over 313m users, Badoo is great for chatting, making friends, sharing interests, and even dating!” reads Badoo's website.

Leaked Source provided three chunks of data to Motherboard, each containing 10,000 records. Out of 100 accounts tested across the three samples, 54 were linked to an active account on Badoo, while 23 indicated that an account had been created, but that the user had not completed registration by clicking the confirmation link emailed to them.

Messages sent to many of the email addresses linked to accounts on Badoo did not successfully deliver. Motherboard is yet to hear back from any of the apparent victims, and we will update this article if we receive a response.

In all, the data dump apparently contains 127,343,437 records. Motherboard was unable to confirm whether the dump was indeed this large, but another source who also obtained the data reported a similar figure.

Passwords in the samples provided to Motherboard were hashed with MD5, a hashing algorithm that has long been trivial for hackers to crack. According to Leaked Source, nearly 50,000 of the passwords in the datadump were “badoo”. No one Motherboard spoke to who was in possession of the dump knew exactly when the data was hacked.

For its part, Badoo denied being the source of the stolen accounts.

“Badoo takes privacy and security extremely seriously. Badoo has not been hacked and our user records/accounts are secure. We monitor our security constantly, and take extreme measures to protect our user base. We were made aware of an alleged data breach, which upon a thorough investigation into our system, we can confirm did not take place,” Badoo spokesperson Joelle Hadfield told Motherboard in an email.

That statement is near identical to another issued recently. In May, hackers claimed to have obtained over 50 million records from another dating site called Zoosk. As Motherboard and tech news site ZDNet found, that data was, however, likely not sourced from Zoosk. ZDNet approached Badoo when many of the supposed 'Zoosk' email addresses had the domain “@mobile.badoo.com.”

Curiously, 28,685,533 unique email addresses in the 'Zoosk' data also appeared in the Badoo data dump, according to Leaked Source. The exact connection between the two datasets is not clear at this stage, nor if they overlap in any other ways.

Regardless, details on Badoo users are being actively traded, and perhaps more than was previously known.

The lesson: As we've seen over the past week, sometimes data breaches take years to come to light. Users can't rely on waiting for a hack to go public, or for a company to acknowledge it. With that in mind, users should be thinking proactively, and taking steps to protect all their online accounts, even if one site they use does happen to be breached. One way of doing that is with a password manager, which generates strong, unique passwords and stores them either locally or online. That way, when one site is attacked, any details leaked won't necessarily allow hackers to access any other accounts.

Read previous installments of Another Day, Another Hack here.

Let's block ads! (Why?)

Another Day, Another Hack: User Accounts of Dating Site Badoo

Another Day, Another Hack: Furry Site Hacked, Content Deleted

lundi 23 mai 2016

Quite literally, every day someone gets hacked. Whether that's a telecommunications company having its customer data stolen, or another chain of businesses being ripped for all the credit cards it processes, today one hack just seems to melt into another.

In our series Another Day, Another Hack, we do short posts giving you what you need to know about the hack, so you can figure out whether your bank account, website logins or anything else might be at risk. Because, even if the hack might not be the most sophisticated, real people are still getting fucked over somewhere, and should know about it.


Last week, a community of furries—people with an interest in anthropomorphic animal characters such as wolves and foxes—witnessed a popular online hub disappearing. Content including art submissions and user profiles on enthusiast site “Fur Affinity” was wiped, and hackers may have run off with email addresses and hashed passwords.

“We have just learned the attackers have access to personal user data, such as encrypted passwords and email addresses,” the site’s self-described Director of Operations, known as “Chase,” wrote last Friday on the Fur Affinity forums. Around Monday morning, a user called Fender announced that site passwords had been reset.

The Fur Affinity Twitter account has some 41,000 followers, and describes the site as “The world’s largest community of furries, anthros, dragons and more!” Fur Affinity, essentially an online gallery, allows users to upload music, writing, and art.

According to Fender, the problems started at the beginning of May, when researchers disclosed a vulnerability in the ImageMagick library that allows attackers to execute arbitrary code on websites. In this case, hackers downloaded Fur Affinity's source code before the administrators had patched the site.

Over a week later, Fur Affinity heard that people at an unnamed convention were handing out USB sticks containing that source code. The same day, the site was attacked again, and this time hackers deleted content. They were stopped before things such as journals and notes could be wiped, an administrator who calls themselves Dragoneer wrote last week on the Fur Affinity forums.

“While we were investigating [the USB sticks], somebody launched a second attack against the site using information gleaned from the source code,” Dragoneer said.

Fender wrote that, “At this time we do not know who executed the attacks on this site. An analysis of the attack vector used suggests these individual(s) were experienced attackers and not casual bystanders.” (However, the researchers who discovered the ImageMagick vulnerability said that the “exploit is trivial.”)

Fur Affinity has been restored from a May 11 backup, so the damage isn't too bad, and site passwords are supposedly hashed and salted. This means they might not be immediately cracked, though that is still possible.

The lesson: Even if a site, organisation or company says that no passwords have been stolen in an attack, you should reset yours anyway, especially if you used the same password on multiple services.

Let's block ads! (Why?)

Another Day, Another Hack: Furry Site Hacked, Content Deleted

Another Day, Another Hack: 117 Million LinkedIn Emails And Passwords

mercredi 18 mai 2016

Quite literally, every day someone gets hacked. Whether that's a telecommunications company having its customer data stolen, or another chain of businesses being ripped for all the credit cards it processes, today one hack just seems to melt into another.

In our series Another Day, Another Hack, we do short posts giving you what you need to know about the hack, so you can figure out whether your bank account, website logins or anything else might be at risk. Because, even if the hack might not be the most sophisticated, real people are still getting fucked over somewhere, and should know about it.


A hacker is trying to sell the account information, including emails and passwords, of 117 million LinkedIn users.

The hacker, who goes by the name “Peace,” told Motherboard that the data was stolen during the LinkedIn breach of 2012. At the time, only around 6.5 million encrypted passwords were posted online, and LinkedIn never clarified how many users were affected by that breach.

Turns out it was much worse than anybody thought.

Peace is selling the data on the dark web illegal marketplace The Real Deal for 5 bitcoin (around $2,200). The paid hacked data search engine LeakedSource also claims to have obtained the data. Both Peace and the one of the people behind LeakedSource said that there are 167 million accounts in the hacked database. Of those, around 117 million have both emails and encrypted passwords.

“It is only coming to the surface now. People may not have taken it very seriously back then as it was not spread,” one of the people behind LeakedSource told me. “To my knowledge the database was kept within a small group of Russians.”

A screenshot of the listing on The Real Deal

LeakedSource provided Motherboard with a sample of almost one million credentials, which included email addresses, hashed passwords, and the corresponding hacked passwords. The passwords were originally encrypted or hashed with the SHA1 algorithm, with no “salt,” which is a series of random digits attached to the end of hashes to make them harder to be cracked.

One of the operators of LeakedSource told Motherboard in an online chat that so far they have cracked “90% of the passwords in 72 hours.”

Troy Hunt, a security researcher who maintains the breach notification site “Have I Been Pwned?,” reached out to some of the victims of the data breach. Two of them confirmed to Hunt that they indeed were users of LinkedIn and that the password he shared with them was the one they were using at the time of the breach. Motherboard was able to confirm a third victim.

One of the victims told Motherboard that the password in the sample was their current one, though he changed it as soon as Hunt reached out no notify him of the breach.

“Having a password out there feels like someone being able to let themselves in to your private space whenever they like, without you knowing,” the victim, who asked to remain anonymous, said in an email.

When reached for comment on Tuesday, LinkedIn spokesperson Hani Durzy told Motherboard that the company’s security team was looking into the incident, but that at the time they couldn’t confirm whether the data was legitimate. Durzy, however, also admitted that the 6.5 million hashes that were posted online in 2012 were not necessarily all of the passwords stolen.

“We don’t know how much was taken,” Durzy told me in a phone call.

The lesson: For LinkedIn, the lesson is the same as four years ago: don’t store password in an insecure way. As for LinkedIn users, if you didn’t already change your password four years ago, change it again, especially if you use it on other services (and please stop reusing passwords).

“The prevalence of password reuse means we’ll see that unlock other accounts too,” Hunt told me.

Another lesson is that even old hacked data can sometimes be valuable, given that some of these passwords might still be valid.

Let's block ads! (Why?)

Another Day, Another Hack: 117 Million LinkedIn Emails And Passwords

Another Day, Another Hack: Is Your Fisting Site Updating Its Forum Software?

mardi 10 mai 2016

Ce résumé n'est pas disponible. Veuillez cliquer ici pour afficher l'article.

Another Day, Another Hack: Passwords and Sexual Desires for Dating Site 'Fling'

vendredi 6 mai 2016

Ce résumé n'est pas disponible. Veuillez cliquer ici pour afficher l'article.

Another Day, Another Hack: Tens of Millions of Neopets Accounts

jeudi 5 mai 2016

Quite literally, every day someone gets hacked. Whether that's a telecommunications company having its customer data stolen, or another chain of businesses being ripped for all the credit cards it processes, today one hack just seems to melt into another.

In our series Another Day, Another Hack, we do short posts giving you what you need to know about the hack, so you can figure out whether your bank account, website logins or anything else might be at risk. Because, even if the hack might not be the most sophisticated, real people are still getting fucked over somewhere, and should know about it.

Tens of millions of user accounts from virtual pets community Neopets have allegedly been hacked and traded on the criminal underground.

Neopets, owned by games company JumpStart, is a website that allows players to care for digital “pets,” and buy items for them with virtual currency. Users signup with an email address, and provide a limited amount of personal information, such as their gender, country, state, and date of birth.

Motherboard obtained a sample of 100,000 apparent Neopet user accounts. Out of 100 randomly selected usernames, 83 corresponded to ones on Neopets. No apparent victims included in the Neopets breach responded to requests for comment, although the emails did deliver successfully.

Not all of the records contained every piece of information. For example, some accounts did not seem to include an email address. Why this was the case is unclear.

“After investigating the sample dataset of 100,000 records you forwarded, we have determined that the dataset was dated several years ago, prior to our Neopets acquisition,” Jim Czulewicz, chief revenue officer for JumpStart told Motherboard in an emailed statement. JumpStart acquired Neopets in 2014.

“Regardless, Neopets and our customers were the victim of a cyberattack and likely criminal activity. We plan to notify all users about the incident and advise them to reset their password. The security of our users' personal information has always been a top priority for our company,” Czulewicz continued.

“It is important to note that no credit card or physical address information was included in the dataset and Neopets does not store any customer credit card or other payment information, so that specific data is not at risk of ever being compromised. Our brand is about creating joy and entertainment in the lives of our users and we are committed to always ensuring that experience is delivered in a secure, safe environment,” he added.

The number of records hacked allegedly totaled over 70 million, but Motherboard was unable to confirm this. At the time of writing, Neopets has in excess of 90 million users.

This isn't the first time hackers have seemingly gone after Neopets. According to a September 2015 report, hackers planned to release records on every user of the site. It is not totally clear whether that breach, and this latest data set, are connected.

The lesson: As Czulewicz recommended, any Neopets users, even if they no longer play on the site, should change their password. With the information in the dump, a hacker could potentially access other services if they are protected with the same password.

Let's block ads! (Why?)

Another Day, Another Hack: Tens of Millions of Neopets Accounts

Another Day, Another Hack: Millions of User Accounts for Streaming App '17'

vendredi 29 avril 2016

Quite literally, every day someone gets hacked. Whether that's a telecommunications company having its customer data stolen, or another chain of businesses being ripped for all the credit cards it processes, today one hack just seems to melt into another.

In our series Another Day, Another Hack, we do short posts giving you what you need to know about the hack, so you can figure out whether your bank account, website logins or anything else might be at risk. Because, even if the hack might not be the most sophisticated, real people are still getting fucked over somewhere, and should know about it.


A hacker is advertising a cache of email addresses, poorly secured passwords, phone numbers, and other information from users of photo sharing and video streaming app '17', which is particularly popular in Asia.

The data is being sold on The Real Deal, a dark web market that specialises in stolen information and computer exploits.

The data was allegedly obtained via an app server, and not the company's website, the hacker advertising the data told Motherboard in an encrypted chat.

“Vuln[erability] and some shit security,” the hacker, who used the handle “peace,” said.

Peace shared a small sample along with his listing. Out of 54 usernames that Motherboard tested with the 17 app, 52 already corresponded to accounts. (The other two usernames contained characters, such as underscores, that Motherboard was unable to enter into the Android version of the app).

Motherboard then obtained a larger sample, allegedly containing information on 20,000 users. Many of these usernames also matched active accounts on 17.

The passwords were hashed using the notoriously weak MD5 algorithm. Because of this, Motherboard was quickly able to obtain users' full passwords by using simple online tools.

The data also includes email addresses, phone numbers, IP addresses, and information about a user's phone, such as the model and operating system.

Motherboard attempted to contact 26 users via their email address. One person confirmed they were a user of 17, but said he had un-installed the app. In the samples Motherboard reviewed, not every entry contained all pieces of information. For example, some didn’t include phone numbers, and others didn’t include email addresses. This might be due to the fact the users can sign up to 17 using their Facebook account, rather than their phone number.

“We take every threat to personal user data and security with the utmost priority,” Popo Chen, the co-founder of the app, wrote in an email after being informed of the apparent breach by Motherboard. Chen did not confirm the legitimacy of the data.

In September 2015, 17 Media, the company that makes 17, raised $10 million in Series A funding. At the time, 17 had been downloaded over six million times, according to Silicon Angle. In a similar vein to YouTube, the app has a sharing system, in which users who create content split ad revenue with 17 Media. According to the Google Play Store, the app has between 500,000 and 1 million installs.

In all, the hacker claims to have obtained information on 30 million users. Motherboard could not confirm whether Peace is selling that many accounts.

It's unclear why the discrepancy between the apparent number of 17 downloads and the 30 million user account figure is so wide. Chen did not respond when asked to clarify how many users 17 has.

Motherboard shared the smaller sample with Chen, who said the “data looks unusual, we don't have any APIs that query this small of a set.” On Thursday, Chen said that the company was “in the process” of buying the data from Peace.

At the time of writing, Peace has sold the data twice, according to the feedback function on The Real Deal, and the hacker said that another sale was pending. One sale is rated as positive, and commented with “quick delivery.” The other sale is marked as negative. It's unclear why the buyer was seemingly unsatisfied with their purchase. The data is being sold for 0.3305 bitcoin (just under $150).

The lesson: All 17 users should immediately change their password as a precauation, in order to avoid third party access to their account. They should also change credentials on any other sites or services that used the same password.

Let's block ads! (Why?)

Another Day, Another Hack: Millions of User Accounts for Streaming App '17'

Another Day, Another Hack: 7 Million Accounts for Minecraft Community ‘Lifeboat’

mardi 26 avril 2016

Image: Pabkov/Shutterstock

Quite literally, every day someone gets hacked. Whether that's a telecommunications company having its customer data stolen, or another chain of businesses being ripped for all the credit cards it processes, today one hack just seems to melt into another.

In our series Another Day, Another Hack, we do short posts giving you what you need to know about the hack, so you can figure out whether your bank account, website logins or anything else might be at risk. Because, even if the hack might not be the most sophisticated, real people are still getting fucked over somewhere, and should know about it.


Over seven million user accounts belonging to members of Minecraft community “Lifeboat” have been hacked, according to security researcher Troy Hunt.

Hunt said he will upload the data to his breach notification website “Have I Been Pwned?”, which allows people to check if their account is compromised, on Tuesday, and that it includes email addresses and weakly hashed passwords—meaning that hackers could likely obtain full passwords from some of the data.

“The data was provided to me by someone actively involved in trading who's sent me other data in the past,” Hunt, who has verified the data and sent Motherboard a redacted screenshot of some of it, said in an email.

Lifeboat runs servers for custom, multiplayer environments of Minecraft Pocket Edition—the smartphone version of the game—which allow Minecraft players to participate in different game modes, such as capture the flag or survival. To join the community, players download the normal Pocket Edition app, connect to a Lifeboat server, and register a username with an email address and password.

Hunt put Motherboard in touch with several victims of the breach, who said they had not been informed by Lifeboat of the hack.

“No lifeboat has not notified me of anything. Looks like they want to keep it [quiet], which I guess isn't that fair,” one user called Tyler, who said he was from Airdrie, Canada, told Motherboard in an email.

“They either didn't even notice yet or just don't care,” said a player named Henni.

“It's bad that they were breached in the first place, but not telling us about it is even worse,” Ali, who said they were from Wisconsin, added.

Lifeboat said it had been aware of the breach for some time.

“When this happened [in] early January we figured the best thing for our players was to quietly force a password reset without letting the hackers know they had limited time to act,” a Lifeboat representative said in an email. “We did this over a period of some weeks. We retain no personal information (name, address, age) about our players, so none was leaked.”

“We have not received any reports of anyone being damaged by this,” the representative added in another email. They did not reply when asked to clarify why the company did not inform users. The three players Motherboard spoke to said they had not received a password reset.

Although the passwords in the breach were hashed, they were done so with the notoriously weak MD5 algorithm, meaning that plenty of the passwords could be figured out with the use of online tools.

“I was able to easily verify people's passwords with them simply by Googling them, such is the joy of unsalted MD5,” Hunt said. Motherboard confirmed that one of the hashes provided by Hunt corresponded to an easily guessable password. The Lifeboat representative said that the company now uses a stronger hashing algorithm.

Naturally, if victims have used the same passwords on other services, such as their email, anyone in possession of the data has a chance of accessing those accounts too.

Lifeboat's approach to security appears to be demonstrated in a how-to guide on its website. “By the way, we recommend short, but difficult to guess passwords. This is not online banking,” it reads.

The lesson: If you care about the security of your accounts, you should really be using strong, unique passwords for each. That way, when a breach occurs on one service—and they will clearly happen—hackers will only be able to access that specific account.

Let's block ads! (Why?)

Another Day, Another Hack: 7 Million Accounts for Minecraft Community ‘Lifeboat’