Yahoo! Voice hacked; 400,000+ login credentials dumped online
|
by Anuradha Shetty
|
|
Hackers belonging to a hacking collective called D33Ds Company have retrieved and dumped login details of more than 400,000+ user accounts in plain text. A post on Trustedsec stated, "The passwords contained a wide variety of email addresses including those from yahoo.com, gmail.com, aol.com, and much more." Interestingly, the post adds that the affected website is a sub-domain of yahoo.com, and that the compromised server may be Yahoo! Voice a.k.a Associated Content. "The affected website was only named as a sub-domain of yahoo.com. However, digging through and searching for the hostname, the attacker forgot to remove the hostname “dbb1.ac.bf1.yahoo.com” (credit to Mubix for the hostname find)," Trustedsec wrote. The most worrisome bit here is that the passwords that were stored were completely unencrypted, and as you're reading this, 400,000+ login credentials (comprising usernames and passwords) have been exposed.
It has been brought to light that the hackers used a union-based SQL injection attack to get away with the information stored in the database. The post on Trustedsec also put forth a glimpse of what the data leaked online looks like (can be seen in the image below). ![]() Screenshot of a part of the details compromised
A note at the end of the dump reads, "We hope that the parties responsible for managing the security of this sub-domain will take this as a wake-up call and not as a threat. There have been many security holes exploited in webservers belonging to Yahoo! Inc. that have caused far greater damage than our disclosure. Please do not take them lightly. The sub-domain and vulnerable parameters have not been posted to avoid further damage."
Reporting on the issue, Ars Technica's Dan Goodin wrote that the union-based SQL injection hacking technique used here affects inadequately secured web applications that do not "properly scrutinize text entered into search boxes and other user input fields". He added, "By injecting powerful database commands into them, attackers can trick back-end servers into dumping huge amounts of sensitive information."
Security breach, such as the case in point or the LinkedIn database leak, is emerging as a worrying trend. LinkedIn recently suffered a data breach where passwords of some of the social network's members were compromised. At the time of the incident, LinkedIn engineer Vicente Silveira confirmed on the website's blog that some passwords were "compromised". "We are continuing to investigate this situation," he said.
Image credit: Trustedsec |
Tags: Yahoo! breach , Online Security Breach , Cyber Crime , Cyber Criminals , Cyber Attack ,
SPOTLIGHT
21 May, 2013, 01:00 PM
Apple iPad 5 trial production to begin...
21 May, 2013, 06:32 PM
Norwegian security firm suspects Indian...
21 May, 2013, 07:55 PM
Is Samsung 'mentally enslaving' Indian smartphone buyers...
17 May, 2013, 07:51 PM IST
Your Aadhaar card hasn’t reached you yet? Download e-Aadhaar
17 May, 2013, 01:09 PM IST
Indian girl invents device that can charge phone in 20 seconds
21 May, 2013, 10:33 AM IST
tech2 live: The latest from Google I/O 2013
16 May, 2013, 01:56 PM IST
MouthShut.com petitions SC to protect freedom of expression and quash
09 May, 2013, 07:01 PM IST
Intel tasked with updating yet 'preserving' Stephen Hawking's voice
21 May, 2013, 08:08 PM
Norwegian security firm suspects Indian hand in sophisticated global malware attack
21 May, 2013, 07:55 PM
Google to retire Checkout service in six months
21 May, 2013, 07:28 PM
5 Online test prep sites for GRE
While GRE coaching classes are limited and not necessarily in every city,...
Your Aadhaar card hasn’t reached you yet? Download e-Aadhaar
To avoid all the hassle and with a view to make it convenient for...
We have 5 tech gift ideas that will help you find a gift that will...
Yahoo! will not restrict Tumblr's porn content: CEO Mayer
Jeff Yablon
Wed May 22, 03:03:40
Google quietly pulls down SMS Search service
Gnosis Media Group
Wed May 22, 02:20:24
Indian girl invents device that can charge phone in 20 seconds
Sreejith Ks
Wed May 22, 00:54:06
Global smartphone shipments to exceed that
HTC One Google Edition coming soon, tweets
Apple iPad 5 trial production to begin...
10.1-inch Sony Xperia Tablet Z launches at
FIFA 14 and Call of Duty: Ghosts to debut...
Xbox Live to get The Music Room as an...


















reddit

Mixx
Facebook
Twitter
Digg
delicious
MySpace


















