Results 1 to 2 of 2

Thread: What a bunch of yahoos

  1. #1

    Default What a bunch of yahoos

    Or as the Register put it: UNION ALL SELECT here, we, go, again FROM passwords

    In other words: some Yahoo web property got hacked using the tried and true technique of SQL injection... Worse, passwords were stored in plain text, that means over 453K passwords were snaffled and posted to some internet forum. I'm guessing that a fair number of them would also happen to be passwords to Yahoo e-mail accounts and what have you.

    A Yahoo! service has apparently succumbed to a simple database attack that leaked 453,000 unencrypted account passwords online.

    A huge document containing the lifted SQL structures, software variables, usernames and cleartext passwords was linked to from a web forum. In the file, the hackers described the break-in as "a wake-up call and not a threat".

    The data dump included the hostname dbb1.ac.bf1.yahoo.com, which is associated with the blog-like service Yahoo! Voices, TrustedSec reports - although there was some confusion over whether the hacked service was in fact the internet telephone call app Yahoo! Voice.

    Linky:
    http://arstechnica.com/security/2012...ervice-hacked/
    http://blog.eset.se/statistics-about...text-accounts/

    So to summarise it is 2012 and Yahoo apparently treats your accounts like it's still stuck in 1992. Consider moving at the first chance.

    For those who don't know what SQL injection is I hope you are not doing *anything* which involves some sort of SQL database much less any which contains some account of mine.
    - Tellos Athenaios
    CUF tool - XIDX - PACK tool - SD tool - EVT tool - EB Install Guide - How to track down loading CTD's - EB 1.1 Maps thread


    ὁ δ᾽ ἠλίθιος ὣσπερ πρόβατον βῆ βῆ λέγων βαδίζει” – Kratinos in Dionysalexandros.

  2. #2
    Needs more flowers Moderator drone's Avatar
    Join Date
    Dec 2004
    Location
    Moral High Grounds
    Posts
    9,286

    Default Re: What a bunch of yahoos

    Quote Originally Posted by Tellos Athenaios View Post
    So to summarise it is 2012 and Yahoo apparently treats your accounts like it's still stuck in 1992. Consider moving at the first chance.

    For those who don't know what SQL injection is I hope you are not doing *anything* which involves some sort of SQL database much less any which contains some account of mine.
    Plaintext passwords and URL DB queries, well done Yahoo!

    My favorite stories are the ones where the Googlebot hacks the DB.
    The .Org's MTW Reference Guide Wiki - now taking comments, corrections, suggestions, and submissions

    If I werent playing games Id be killing small animals at a higher rate than I am now - SFTS
    Si je n'étais pas jouer à des jeux que je serais mort de petits animaux à un taux plus élevé que je suis maintenant - Louis VI The Fat

    "Why do you hate the extremely limited Spartan version of freedom?" - Lemur

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Single Sign On provided by vBSSO