Yahoo! confirms vulnerability fixed
|
by Anuradha Shetty
|
|
Yesterday, Yahoo! confirmed that the data comprising 400,000+ email and passwords that was leaked online in plain text had been sourced from their servers. In an official post on its ycorpblog, Yahoo! now asserts that they have taken "swift action" and fixed the vulnerability. In the post, Yahoo! also informs that they have put in place additional security measures for users who were affected by the data breach. They go onto add that they have "enhanced" their security controls and are currently informing those users affected by the data breach. In their blog post, Yahoo! assures that they will take significant measures to protect their users and their data. ![]() Yahoo! confirms fixing vulnerability (Image credit: Getty Images)
The company further in their post adds, "If you joined Associated Content prior to May 2010 using your Yahoo! email address, please log in to your Yahoo! account where you may be prompted to answer a series of authentication questions to change and validate your credentials."
One of our previous articles, detailing on the data breach, quoted Yahoo! as revealing that, "older file from Yahoo! Contributor Network (previously Associated Content) containing approximately 400,000 Yahoo! and other company users names and passwords was stolen yesterday, July 11." Yahoo! went on to confirm that of the entire lot of e-mail ids and passwords compromised, less than five percent of the Yahoo! accounts had valid passwords. The company has assured in the note that it is fixing the loophole that led to the breach, while also changing the passwords of the affected accounts. They are also informing companies whose user accounts may have been affected by the breach. Yahoo! has also notified its users to change their passwords regularly, and also make themselves aware of online safety tips at security.yahoo.com.
Hackers belonging to a hacking collective called D33Ds Company recently managed to retrieve and subsequently dump login details of more than 400,000+ user accounts in plain text. The most worrisome bit there was that the stored passwords were completely unencrypted. It has been brought to light that the hackers used a union-based SQL injection attack to get away with the information stored in the database. A note at the end of the dump reads, "We hope that the parties responsible for managing the security of this sub-domain will take this as a wake-up call and not as a threat. There have been many security holes exploited in webservers belonging to Yahoo! Inc. that have caused far greater damage than our disclosure. Please do not take them lightly. The sub-domain and vulnerable parameters have not been posted to avoid further damage." |
Tags: Yahoo! breach , Online Security Breach , Cyber Crime , Cyber Criminals , Cyber Attack , Yahoo! apology , Associated Content , Yahoo! Contributor Network
SPOTLIGHT
Steve Jobs talks legacy and obsolete...
20 Jun, 2013, 12:31 PM
Google to open Android Nation stores in...
20 Jun, 2013, 11:23 AM
Aping Vodafone, Airtel slashes prepaid 2G...
20 Jun, 2013, 09:37 AM
Yahoo! assures it has ID recycling under control
20 Jun, 2013, 12:30 PM IST
Digg Reader to go live for all users on June 26
18 Jun, 2013, 10:08 AM IST
Google to create industry-wide database to banish child pornography
17 Jun, 2013, 10:06 AM IST
Vines more shared on Twitter than Instagram images now
09 Jun, 2013, 11:16 AM IST
Google Reader dead because of smartphone users: Google
07 Jun, 2013, 01:36 PM IST
LinkedIn back up after hour-long outage following DNS issue
20 Jun, 2013, 01:21 PM
Yahoo! assures it has ID recycling under control
20 Jun, 2013, 12:30 PM
Evernote Web Clipper for Chrome lets you clip from Gmail
19 Jun, 2013, 04:40 PM
5 Websites to buy cool and quirky gadgets
If you like collecting some really cool and bizarre stuff, or you are...
High-speed Internet plans in India
We can pin our hopes on ISPs who are now providing Internet speeds over...
The state of Internet connectivity in India
A decade ago Internet connectivity may have been considered a luxury, but...
5 Websites to buy cool and quirky gadgets
Anshu Rai Inleague
Thu Jun 20, 14:46:05
Aping Vodafone, Airtel slashes prepaid 2G rates by 90 percent in Punjab, Haryana
Punit
Thu Jun 20, 13:54:52
PlayStation 4 up for pre-order in India
Shishir Mukherjee
Thu Jun 20, 13:48:06
Google to open Android Nation stores in...
Microsoft considered buying Nokia's...
Microsoft to use Qualcomm chips on...
Sony Xperia Tablet Z (SGP321) Review
New MacBook Air coming soon to India;...
Alienware shows three new gaming notebooks
Gog.com kicks off summer sale with a free...
PC version of Assassin's Creed 4:...


















reddit

Mixx
Facebook
Twitter
Digg
delicious
MySpace




















