Page 1 of 2 12 LastLast
Results 1 to 16 of 26

Thread: News - Hackers expose 450,000 Yahoo accounts

  1. #1
    HEXUS.admin
    Join Date
    Apr 2005
    Posts
    18,673
    Thanks
    0
    Thanked
    355 times in 190 posts

    News - Hackers expose 450,000 Yahoo accounts

    Gmail, AOL, Hotmail and MSN accounts and others also compromised.
    Read more.

  2. #2
    Hexus.Communism GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    9,418
    Thanks
    465
    Thanked
    954 times in 741 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage II Extreme full WC
      • CPU:
      • i7 920 @4ghz WC
      • Memory:
      • 12gb Corsair Dominator
      • Storage:
      • intel 160gb X25m + Raptor 320gb RAID0
      • Graphics card(s):
      • 2 GTX480's in SLI under water.
      • PSU:
      • Enermax Galaxy 1250
      • Case:
      • Corsair 800D
      • Operating System:
      • win7 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 10mb Cable

    Re: News - Hackers expose 450,000 Yahoo accounts

    oh joy...

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  3. #3
    Senior Member
    Join Date
    May 2010
    Location
    Southampton
    Posts
    503
    Thanks
    24
    Thanked
    25 times in 20 posts
    • cameronlite's system
      • Motherboard:
      • ASUS P5K Premium
      • CPU:
      • Intel Q6600
      • Memory:
      • 4GB Corsair 1333mhz
      • Storage:
      • 128GB Corsair Force 3 SSD
      • Graphics card(s):
      • MSI Twin Frozr AMD 5850 1GB
      • PSU:
      • XILENCE 600W
      • Case:
      • Lian Li P50r AMD Limited Edition
      • Operating System:
      • Windows 8 Professional 64 bit
      • Monitor(s):
      • Acer 243W 24", HP LA2405 24", Dell 2405 24"
      • Internet:
      • Virgin - 30Mb

    Re: News - Hackers expose 450,000 Yahoo accounts

    Another nail in the Yahoo coffin.
    Currently studying: Electronic Engineering and Artificial Intelligence at the University of Southampton.

  4. #4
    Senior Member Hicks12's Avatar
    Join Date
    Jan 2008
    Location
    Plymouth-SouthWest
    Posts
    6,309
    Thanks
    1,024
    Thanked
    288 times in 255 posts
    • Hicks12's system
      • Motherboard:
      • Asus P8Z68-V
      • CPU:
      • Intel i5 2500k@4ghz, cooled by EK Supreme HF
      • Memory:
      • 8GB Kingston hyperX ddr3 PC3-12800 1600mhz
      • Storage:
      • 64GB M4/128GB M4 / WD 640GB AAKS / 1TB Samsung F3
      • Graphics card(s):
      • Palit GTX460 @ 900Mhz Core
      • PSU:
      • 675W ThermalTake ThoughPower XT
      • Case:
      • Lian Li PC-A70 with modded top for 360mm rad
      • Operating System:
      • Windows 7 Professional 64bit
      • Monitor(s):
      • Dell U2311H IPS
      • Internet:
      • 10mb/s cable from virgin media

    Re: News - Hackers expose 450,000 Yahoo accounts

    Have i missed something or has this piece of turd group actually released the details in full (i.e not with half of it blurred, did you add this? ). If they did just throw it out well they will end up with a swift punch in the face if i ever meet them, im fed up with little groups like this that think its cool or they're doing people a favour, they arent doing anything good... a wake up call yeah flipping right, if you wanted to give yahoo a wake up call you would have sent them all these details NOT thrown them on the web to hurt CONSUMERS/THE FRACKING PUBLIC.

    These people are bloody retards, oh yeah lets gain access to peoples accounts and credit details and release them to public to shove it to the big corporations, instead they make hassle for the public and have basically got spam bots and other **** things selling their credit details etc.

    never signed up with yahoo so shouldnt effected but still makes my blood boil, flipping pricks.
    Quote Originally Posted by snootyjim View Post
    Trust me, go into any local club and shout "I've got dual Nehalem Xeons" and all of the girls will practically collapse on the spot at the thought of your e-penis

  5. #5
    Senior Member watercooled's Avatar
    Join Date
    Jan 2009
    Posts
    7,396
    Thanks
    1,245
    Thanked
    562 times in 497 posts

    Re: News - Hackers expose 450,000 Yahoo accounts

    It's completely laughable and unacceptable that any company should hold passwords in plaintext, let alone one as huge as Yahoo. It's not exactly rocket science!

  6. #6
    Hexus.Communism GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    9,418
    Thanks
    465
    Thanked
    954 times in 741 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage II Extreme full WC
      • CPU:
      • i7 920 @4ghz WC
      • Memory:
      • 12gb Corsair Dominator
      • Storage:
      • intel 160gb X25m + Raptor 320gb RAID0
      • Graphics card(s):
      • 2 GTX480's in SLI under water.
      • PSU:
      • Enermax Galaxy 1250
      • Case:
      • Corsair 800D
      • Operating System:
      • win7 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 10mb Cable

    Re: News - Hackers expose 450,000 Yahoo accounts

    my email wasnt on it, and yes emailassword.

    best to follow the link in the pic and check if your one of them.

    and yes the day i meet someone who admits to releasing stuff like this will get a thumb in each eye.

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  7. #7
    Registered+
    Join Date
    Dec 2003
    Location
    Spalding
    Posts
    80
    Thanks
    59
    Thanked
    6 times in 5 posts
    • mtyson's system
      • Motherboard:
      • Gigabyte G31M-ES2L
      • CPU:
      • Pentium E6300
      • Memory:
      • 2GB
      • Storage:
      • Seagate 750GB HDD
      • Graphics card(s):
      • Radeon X1600 Pro
      • PSU:
      • came with case
      • Case:
      • old HP Pavilion Celeron case
      • Operating System:
      • Windows 7
      • Monitor(s):
      • LG L2010P 1600x1200
      • Internet:
      • 4.5 Mb PlusNet

    Re: News - Hackers expose 450,000 Yahoo accounts

    The user : pass details were published in full in a big plain text list on their web site. No details were obfuscated by the hackers.
    Last edited by mtyson; 12-07-2012 at 11:15 PM. Reason: odd smiley appeared

  8. #8
    Senior Member watercooled's Avatar
    Join Date
    Jan 2009
    Posts
    7,396
    Thanks
    1,245
    Thanked
    562 times in 497 posts

    Re: News - Hackers expose 450,000 Yahoo accounts

    It's currently down due to high traffic so can't check. Doubt I'll be on it but not a problem to change some passwords anyway...

  9. #9
    Militant Battle Moose! CAT-THE-FIFTH's Avatar
    Join Date
    Aug 2006
    Location
    Planet Of The Moose
    Posts
    18,795
    Thanks
    1,955
    Thanked
    2,838 times in 2,217 posts

    Re: News - Hackers expose 450,000 Yahoo accounts

    Domains affected:

    Domains
    1. Yahoo.com (137,559)
    2. Gmail.com (106,873)
    3. Hotmail.com (55,148)

    4. Aol.com (25,521)
    5. Comcast.net (8,536)
    6. Msn.com (6,395)
    7. Sbcglobal.net (5,193)
    8. Live.com (4,313)
    9. Verizon.net (3,029)
    10. Bellsouth.net (2,847)
    11. Cox.net (2,260)
    12. Yahoo.co.in (2,133)
    13. Ymail.com (2,077)
    14. Hotmail.co.uk (2,028)
    15. Earthlink.net (1,943)
    16. Yahoo.co.uk (1,828)
    17. Aim.com (1,611)
    18. Charter.net (1,436)
    19. Att.net (1,372)
    20. Mac.com (1,146)

  10. #10
    Senior Member watercooled's Avatar
    Join Date
    Jan 2009
    Posts
    7,396
    Thanks
    1,245
    Thanked
    562 times in 497 posts

    Re: News - Hackers expose 450,000 Yahoo accounts

    Yeah that is pretty scary, what's Yahoo doing with plaintext Gmail/Hotmail passwords? Unless I've misunderstood...

  11. #11
    Militant Battle Moose! CAT-THE-FIFTH's Avatar
    Join Date
    Aug 2006
    Location
    Planet Of The Moose
    Posts
    18,795
    Thanks
    1,955
    Thanked
    2,838 times in 2,217 posts

    Re: News - Hackers expose 450,000 Yahoo accounts

    It seems to be connected with something called Yahoo Voices:

    http://mashable.com/2012/07/12/yahoo-voices-hacked/

    "But it wasn’t just Yahoo! email addresses that have been infiltrated: Gmail, MSN, Hotmail, Comcast and AOL accounts have also been hacked. (Yahoo! Voices allows you to sign in with non-Yahoo! email addresses.)"

  12. #12
    Lurking since 06
    Join Date
    May 2006
    Location
    London
    Posts
    524
    Thanks
    50
    Thanked
    37 times in 22 posts
    • Mama Sumae's system
      • Motherboard:
      • Asus P5B - deluxe
      • CPU:
      • Core2 duo 6300 O'c @ 3.1 Mhz / Arctic Cooling Freezer 7 Pro
      • Memory:
      • Corsair 2GB XMS2 6400 C4 @ 890Mhz
      • Storage:
      • WD 320 GB /sata
      • Graphics card(s):
      • Gigabyte GTX 560 Ti oc - 1GB GDDR5
      • PSU:
      • Enermax NoisetakerII 485W
      • Case:
      • AKASA ZEN Black 2x12cm fans
      • Operating System:
      • Win 7 Ulti
      • Monitor(s):
      • BenQ G2222HDL 21.5 inch
      • Internet:
      • Virginmedia 50MB (or so they told me...)

    Re: News - Hackers expose 450,000 Yahoo accounts

    I am such a cynic that my first thought was how helpful this news is for those advocating more internet policing.

  13. #13
    Zzzzzzz sleepyhead's Avatar
    Join Date
    Nov 2007
    Posts
    2,508
    Thanks
    370
    Thanked
    292 times in 162 posts

    Re: News - Hackers expose 450,000 Yahoo accounts

    Does this also include Flickr?

  14. #14
    Member
    Join Date
    Jul 2012
    Posts
    164
    Thanks
    11
    Thanked
    13 times in 8 posts

    Re: News - Hackers expose 450,000 Yahoo accounts

    This just goes to prove how aged yahoo platform really is and how lazy most of their programmers are. Or plain stupid? Not much of a difference, really. Any semi-decent web programmer (or indeed any other programmers that moved past "knowledge" gathered in those nice black & yellow booklets) will know better than to store user passwords directly in a database, and a poorly protected one at that, too. What a bunch of wallies! LOL! For those not in the know - only one-way "bcrypt" (or at the very least SHA256 or extremely well "salted" MD5) hashes of passwords should be stored since those can't be reversed back without insane amounts of processing power ("bcrypt" is considered "a slow algorithm" but still fast enough to verify user input), these hashes stored in a well protected database, hashes never exported for any purpose whatsoever and, of course, never used in any way to store user session data in cookies. Session IDs should also be completely random, long enough to make any brute force hacking near impossible, include a time-stamp on which they can be checked for validity (on top of their existence on the server, of course) and should expire within a reasonably small amount of time. I realize such approach means a minor inconvenience for users have they forgotten their passwords, but there's so many ways around it already in existence, I won't even bother explaining any. "Google" for it and remember you can do better than provide just a few possible password reminder questions than some other big companies do - enable users to also type in their own questions (DUH! Google! LOL). That's it folks, programming web for safe(r) surfing in a nutshell. Can't really trust some "yahoos" on that now, can we?

  15. #15
    Now 100% Apple free cheesemp's Avatar
    Join Date
    Apr 2007
    Location
    Southampton
    Posts
    1,214
    Thanks
    46
    Thanked
    59 times in 42 posts
    • cheesemp's system
      • Motherboard:
      • Gigabyte z77 something or another
      • CPU:
      • Intel i5 3570k @ stock
      • Memory:
      • 8gb
      • Storage:
      • 64Gb M4 SSD + 2x500Gb Sata II drives
      • Graphics card(s):
      • Geforce 285 GTX
      • PSU:
      • Antec 650W
      • Case:
      • Antec 300
      • Operating System:
      • Win7
      • Monitor(s):
      • 23" Samsung LED
      • Internet:
      • 14Mb O2

    Re: News - Hackers expose 450,000 Yahoo accounts

    Quote Originally Posted by howdee View Post
    This just goes to prove how aged yahoo platform really is and how lazy most of their programmers are. Or plain stupid? Not much of a difference, really. Any semi-decent web programmer (or indeed any other programmers that moved past "knowledge" gathered in those nice black & yellow booklets) will know better than to store user passwords directly in a database, and a poorly protected one at that, too. What a bunch of wallies! LOL! For those not in the know - only one-way "bcrypt" (or at the very least SHA256 or extremely well "salted" MD5) hashes of passwords should be stored since those can't be reversed back without insane amounts of processing power ("bcrypt" is considered "a slow algorithm" but still fast enough to verify user input), these hashes stored in a well protected database, hashes never exported for any purpose whatsoever and, of course, never used in any way to store user session data in cookies. Session IDs should also be completely random, long enough to make any brute force hacking near impossible, include a time-stamp on which they can be checked for validity (on top of their existence on the server, of course) and should expire within a reasonably small amount of time. I realize such approach means a minor inconvenience for users have they forgotten their passwords, but there's so many ways around it already in existence, I won't even bother explaining any. "Google" for it and remember you can do better than provide just a few possible password reminder questions than some other big companies do - enable users to also type in their own questions (DUH! Google! LOL). That's it folks, programming web for safe(r) surfing in a nutshell. Can't really trust some "yahoos" on that now, can we?
    Unless I misunderstood - this service was something that allowed Yahoo to log into a users email account held by another company. In which case using hashes wouldn't have worked (It'll only work locally with hashes as you know how to use the hashes). I am disappointed though that they didn't at least obfuscate/encrypt the passwords.

    For local website accounts what you've said is correct though.

  16. #16
    Senior Member watercooled's Avatar
    Join Date
    Jan 2009
    Posts
    7,396
    Thanks
    1,245
    Thanked
    562 times in 497 posts

    Re: News - Hackers expose 450,000 Yahoo accounts

    To be pedantic, you don't have to use bcrypt; SHA256 (or SHA512 which is now Linux default for user passwords) is not inferior as you imply, and ALL passwords should be salted to protect against rainbow table attacks. MD5 is no longer considered suitable for cryptographic hashing. Any hash function should not be reversible, so bruteforcing (or rainbow tables without salt) is the only option; choosing a half decent password is important so bruteforcing is not plausible.

    Even if they were storing credentials for other websites, storing them completely in the clear in a database is pathetic. A company as large as Yahoo should have set up a proper authentication process between themselves and the other party.

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •