another bad day for passwords at yahoo
Last Updated : GMT 09:03:51
Almaghrib Today, almaghrib today
Almaghrib Today, almaghrib today
Last Updated : GMT 09:03:51
Almaghrib Today, almaghrib today

Another bad day for passwords at Yahoo

Almaghrib Today, almaghrib today

Almaghrib Today, almaghrib today Another bad day for passwords at Yahoo

London - Arabstoday

Yahoo confirmed today that a bunch of passwords — more than 450,000 of them, to be exact — have been stolen. The breach of Yahoo’s servers was supposedly the work of a group of hackers that called itself the D33D Company, saying in a post that the action was meant to wake up Yahoo’s computer security team and not for malicious purposes. As data breaches go, the number of accounts compromised wasn’t that large. Earlier this summer, LinkedIn suffered a breach that compromised the passwords of some six million of its customers. In LinkedIn’s case, the passwords were stored in a marginally scrambled state — not strongly encrypted as they should have been, but in a mixed-up state, using an old, easy-to-break hashing technique known as MD5. In the case of Yahoo, the passwords are said to have been stored in raw plaintext, which anyone with even the slightest bit of training in IT security knows is a no-no. If that is indeed how these passwords were stored, then Yahoo has some explaining to do. The attack itself seems to have been carried out using a favorite old hacker technique known as an SQL injection. Basically, a Web application sitting on top of a database is tricked into serving up information because it hasn’t been told not to answer queries for it. In this case, according to Kyle Adams, chief security architect for Mykonos Software, a unit of Juniper Networks, the attack was a variant of SQL injection known as a Union Based attack, in which the database hands over hundreds of passwords in a single go. Since it only takes a small number of requests to yield a lot of information, they’re hard to detect. Yahoo is in damage-control mode. It said in a statement that it “takes security very seriously,” and pointed out that fewer than 5 percent of the Yahoo accounts involved had valid passwords. If that’s the case, then there’s a good chance that many of the passwords its database handed over are expired. Also, there’s no mention of the email addresses and passwords being stored in plaintext, but I doubt there will be. Here’s Yahoo’s full statement: “At Yahoo! we take security very seriously and invest heavily in protective measures to ensure the security of our users and their data across all our products. We confirm that an older file from Yahoo! Contributor Network (previously Associated Content) containing approximately 450,000 Yahoo! and other company users names and passwords was compromised yesterday, July 11. Of these, less than 5% of the Yahoo! accounts had valid passwords. We are taking immediate action by fixing the vulnerability that led to the disclosure of this data, changing the passwords of the affected Yahoo! users and notifying the companies whose users accounts may have been compromised. We apologize to all affected users. We encourage users to change their passwords on a regular basis and also familiarize themselves with our online safety tips at security.yahoo.com.” As you can imagine, security research companies are running fast and furiously to analyze the attack and the data that’s been published so far. I got one interesting file from the people at Rapid7, with whom I talk from time to time. Large numbers are usually an abstraction. If someone says a half-million accounts have been compromised, you can imagine the scale, but it’s harder to get your head around how many people’s accounts may actually be involved. Rapid7′s researchers put together a file with the number of domains seen in email addresses of the compromised accounts: There are 35,000 of them. Below is a list of the top 100 or so which had at least 100 addresses appear in the list. The number to the left is the number of accounts from the given domain. For context: If what Yahoo says is true and only 5 percent of the Yahoo accounts on this list were paired with still-current passwords, then that works out to 6,878 Yahoo accounts compromised. If that rate remains consistent across the entire list, then we’re talking a total of about 23,000 accounts. Rapid7 also shared with me the most common passwords seen in the file taken in the breach. The most common among them? 123456. Yes. Really. The list of passwords, including the number of each found in the list, is after the list of domains.

almaghribtoday
almaghribtoday

Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

another bad day for passwords at yahoo another bad day for passwords at yahoo

 



Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

another bad day for passwords at yahoo another bad day for passwords at yahoo

 



Almaghrib Today, almaghrib today Skincare PR Performance Full Year 2017

GMT 09:22 2018 Monday ,22 January

Skincare PR Performance Full Year 2017
Almaghrib Today, almaghrib today New hunt for flight MH370 gets under way

GMT 11:03 2018 Wednesday ,24 January

New hunt for flight MH370 gets under way
Almaghrib Today, almaghrib today Modern colorful bedroom renovation

GMT 10:57 2017 Thursday ,21 December

Modern colorful bedroom renovation
Almaghrib Today, almaghrib today Puigdemont candidate for Catalan president

GMT 13:56 2018 Tuesday ,23 January

Puigdemont candidate for Catalan president
Almaghrib Today, almaghrib today Turkey detains dozens more

GMT 10:47 2018 Wednesday ,24 January

Turkey detains dozens more

GMT 05:22 2015 Monday ,02 February

Djokovic, Serena live up to top billing

GMT 17:23 2015 Wednesday ,08 April

22 dead in rebel shelling on Yemen's Aden

GMT 13:32 2017 Sunday ,23 April

Strike hits makeshift Syria ‘cave’ hospital

GMT 12:49 2017 Friday ,27 October

Key events since Catalonia's independence vote

GMT 13:12 2011 Tuesday ,13 September

International cartoon festival to open in S China

GMT 13:08 2017 Saturday ,02 December

Russia breathe sigh of relief

GMT 15:29 2012 Thursday ,08 March

NBA: Cleveland 100, Denver 99

GMT 18:03 2016 Tuesday ,09 February

Police Academy will remain training African cadres

GMT 03:27 2013 Wednesday ,06 February

New Citroen DS3 Cabrio

GMT 13:13 2011 Friday ,16 December

Hyundai i-oniq Concept for Geneva 2012

GMT 14:56 2011 Thursday ,15 December

Buick Teases New Encore Crossover

GMT 16:54 2014 Wednesday ,16 July

Mali government 'ready to go far' in peace talks

GMT 09:14 2012 Sunday ,19 August

Sofia Vergara in figure hugging dress
Almaghrib Today, almaghrib today
 
 Almaghrib Today Facebook,almaghrib today facebook  Almaghrib Today Twitter,almaghrib today twitter Almaghrib Today Rss,almaghrib today rss  Almaghrib Today Youtube,almaghrib today youtube  Almaghrib Today Youtube,almaghrib today youtube

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

.almaghribtoday .almaghribtoday .almaghribtoday .almaghribtoday
almaghribtoday almaghribtoday almaghribtoday
almaghribtoday
بناية النخيل - رأس النبع _ خلف السفارة الفرنسية _بيروت - لبنان
almaghribtoday, Almaghribtoday, Almaghribtoday