Skip to main content

How the hackerz hack u

In this case, Yahoo stored its Contributor Network usernames and passwords in plain text, which means the login credentials were immediately intelligible to anyone who broke in.
Security experts say they can tell that the credentials were stored without encryption because many were too long to crack using brute-force techniques.
"Yahoo failed fatally here," said Anders Nilsson, security expert and chief technology officer of Scandinavian security company Eurosecure. "It's not just one specific thing that Yahoo mishandled -- there are many different things that went wrong here. This never should have happened."
Nilsson said Yahoo screwed up on three fronts: The site should have been built more robustly, so it wouldn't have been susceptible to something as simple as a SQL attack. It should have secured users' log-in information, and it should have put the equivalent of trip-wires in place to set off alarm bells when such an easily noticeable break-in occurred.
"I mean, this is Yahoo we're talking about," Nilsson said. "With the security policies it has in place for its other sites, it should have known to at least put up a firewall to detect these kind of things."
Since many people reuse their passwords across multiple websites, Yahoo's security lapse means that all those users' logins are potentially at risk. Even robust passwords are at risk -- the longest password captured in the attack was 31 characters long, which is considered fairly ironclad. However, that password is now attached to an e-mail address and out in the wild for the world to see.
In a written statement, Yahoo said it takes security "very seriously" and is working to fix the vulnerability in its site. It called the captured password list an "older" file, but didn't say how old it was.
The company said it is in the process of changing the passwords of the affected Yahoo users and notifying other companies of their users' compromised accounts.
"We apologize to affected users," the company said in its statement. "We encourage users to change their passwords on a regular basis and also familiarize themselves with our online safety tips at security.yahoo.com."
Yahoo did not respond to a request for comment on why the passwords were stored in plain text.
Yahoo's Contributor Network is a small subsection of Yahoo's enormous network of websites. It consists of a group of freelance journalists who write content for a Yahoo site called Yahoo Voices. The Contributor Network was created last year as an outgrowth of Yahoo's 2010 purchase of Associated Content.
The stolen database predated Yahoo's Associated Content purchase, according to Joseph Bonneau, a Cambridge University researcher who once worked with Yahoo on a password analysis study. He no longer has any official relationship with the company.
"Yahoo can fairly be criticized in this case for not integrating the Associated Content accounts more quickly into the general Yahoo login system, for which I can tell you that password protection is much stronger," Bonneau said.
In a statement appended to the list of stolen credentials, the hackers said that their aim was to scare Yahoo into beefing up its defenses.
"We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call," they wrote. "There have been many security holes exploited in webservers belonging to Yahoo! Inc. that have caused far greater damage than our disclosure. Please do not take them lightly."
The Yahoo hack comes a month after more than 6 million passwords were stolen from several sites including LinkedIn (LNKD) and eHarmony. In that case, the passwords were stored cryptographically, but they weren't randomized -- a weak storage system that security experts have been warning against for years.
Though Yahoo is generally viewed as following industry best practices, some security experts were startled when the University of Cambridge's Bonneau was given 70 million Yahoo passwords by the company for analysis earlier this year.
If Yahoo used a "hash" cryptographic tool and "salt" randomization -- both standard security measures -- the company wouldn't have been able to just send along a list of passwords, they pointed out.
"It's very weird," said Nilsson. "They shouldn't be able to do that."
Yahoo did not reply to requests for comment on how the company's passwords are stored

Popular posts from this blog

picture

This was inside a tunnel in central park, which is where the shadow on left is from. I actually went out to the park with the idea of trying to photograph the wind, which is of course dumb. But I did find a tunnel with dry leaves and gusts of wind. Here I was trying to photograph a single leaf blowin’ in the wind. It also reminds me of a moonscape. circa 1998

Frendzon and Jutaringgit - The end of my precious blogs

Before I continue, I'm happy to announce that I will go to university soon! More on that later. I'm proud it stayed in google's 1st page for 6 years  Hello kids, today I have decided that frendzon(TM) and Jutaringgit(.)com will be deleted once and for all. Thank God for that. This is without reason thought, as you see, frendzon, has actually been inactive for 4 years. I know, I'm really old.    But why is there new posts you may ask, well let me tell you. I have been deleting all of my other blogs for the past 2 years and imported it to frendzon. I hope that that answers your question.   Back in January 2015, my forgetful Lisa has left the group to pursue her love life in America and left me all the frendzon burden to me. That was when I cut all ties with her.  shared by one of my Kedahan writer, Akira  Frendzon was first created to share me and Lisa's love for anime and technology, we garnered considerable amount of...

Problem 1: New UI and other Bugs

Salam taaruf and why hello there! I got news for you and it's the new system UiTM have provided us with, I'm so excited! Well nuggets, say bye bye to course registration.. but WAIT! I found a new quick way to fix this! Method 1(Easiest): You can use incognito mode to register your courses, if the system unavailable still present. Ctrl+R! Method 2(Easy): Go to history and click clear browsing data (Chrome, because who uses Edge 🤣) Tick cookies and cache and proceed to clear data. You're done! Now refresh iStudent portal (This will also improve your chrome performance on windows 10 significantly!) (Warning: You will be log out from most websites) Method 3(Moderate):  First, do method 2 then continue to do method 1. Method 4(Hard): Go beg Muaz in Whatsapp and see if he replies. How to register course? Simple as ice cream First, select register new course. Then, click display group and finally select your class! For ETR300 (MC111 student...