Yahoo Email Security Breach

Started by LongBlade, July 12, 2012, 11:51:53 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

LongBlade

QuoteYahoo Inc. said Thursday it is investigating reports of a security breach that may have exposed nearly half a million users' email addresses and passwords.

Read more: http://www.foxnews.com/tech/2012/07/12/yahoo-investigating-reported-mass-password-breach

Ruh roh.

You know, Yahoo is my major email these days. And I'm terribly concerned that someone has stolen my exclusive offers to access hot women over the internet while I have FedEx deliver pallets of Viagra to my doorstep from totally legit Canadian pharmacies. It really pisses me off that someone might get the same deal as me and be pushing up on my cybersex exclusive chicks.
All that is gold does not glitter,
Not all those who wander are lost;
The old that is strong does not wither,
Deep roots are not reached by the frost.

mirth

QuoteThe little-known group was quoted as saying that they had stolen the passwords using an SQL injection - the name given to a commonly-used attack in which hackers use rogue commands to extract data from vulnerable websites.

SQL injection, awesome. Hey Yahoo the year 2000 called, they'd like their database security back.
"45 minutes of pooping Tribbles being juggled by a drunken Horta would be better than Season 1 of TNG." - SirAndrewD

"you don't look at the mantelpiece when you're poking the fire" - Bawb

"Can't 'un' until you 'pre', son." - Gus

LongBlade

Quote from: mirth on July 12, 2012, 12:58:20 PM
QuoteThe little-known group was quoted as saying that they had stolen the passwords using an SQL injection - the name given to a commonly-used attack in which hackers use rogue commands to extract data from vulnerable websites.

SQL injection, awesome. Hey Yahoo the year 2000 called, they'd like their database security back.

And for the less techno-savvy, a SQL injection attack is not when Star gets a chick drunk and takes her back to his place.
All that is gold does not glitter,
Not all those who wander are lost;
The old that is strong does not wither,
Deep roots are not reached by the frost.

mirth

The best part about many of the major database breaches that happened in the past few years is that they involved fairly simple SQL injection attacks. Often in databases that stored unencrypted user data.
"45 minutes of pooping Tribbles being juggled by a drunken Horta would be better than Season 1 of TNG." - SirAndrewD

"you don't look at the mantelpiece when you're poking the fire" - Bawb

"Can't 'un' until you 'pre', son." - Gus

mirth

"45 minutes of pooping Tribbles being juggled by a drunken Horta would be better than Season 1 of TNG." - SirAndrewD

"you don't look at the mantelpiece when you're poking the fire" - Bawb

"Can't 'un' until you 'pre', son." - Gus

LongBlade

Quote from: mirth on July 12, 2012, 01:07:27 PM
Nice new avatar, LB.

Thanks.

I figured the text to a take on "My other car is a..." would be too long.

Besides, this kinda wraps up all my hobbies in one nifty pic wargaming, zombies, chicks.
All that is gold does not glitter,
Not all those who wander are lost;
The old that is strong does not wither,
Deep roots are not reached by the frost.

Barthheart


LongBlade

All that is gold does not glitter,
Not all those who wander are lost;
The old that is strong does not wither,
Deep roots are not reached by the frost.

mirth

Here's another article on the Yahoo breach-

http://arstechnica.com/security/2012/07/yahoo-service-hacked/

This sorta says it all:

QuoteHackers posted what appear to be login credentials for more than 453,000 user accounts that they said they retrieved in plaintext from an unidentified service on Yahoo.

Login credentials stored in plain text. Happens all too often.
"45 minutes of pooping Tribbles being juggled by a drunken Horta would be better than Season 1 of TNG." - SirAndrewD

"you don't look at the mantelpiece when you're poking the fire" - Bawb

"Can't 'un' until you 'pre', son." - Gus

mirth

#9
Quote from: LongBlade on July 12, 2012, 01:15:20 PM
Quote from: Barthheart on July 12, 2012, 01:14:05 PM
Where's the chicks?

Inside the Jagdpanther with me

Chicks dig the Jagdpanther. Especially the Saukopf mantlet.
"45 minutes of pooping Tribbles being juggled by a drunken Horta would be better than Season 1 of TNG." - SirAndrewD

"you don't look at the mantelpiece when you're poking the fire" - Bawb

"Can't 'un' until you 'pre', son." - Gus

bayonetbrant

you can check to see if your info was part of the breach

http://labs.sucuri.net/?yahooleak
The key to surviving this site is to not say something which ends up as someone's tag line - Steelgrave

"their citizens (all of them counted as such) glorified their mythology of 'rights'...and lost track of their duties. No nation, so constituted, can endure." Robert Heinlein, Starship Troopers

LongBlade

Quote from: mirth on July 12, 2012, 01:17:16 PM
Here's another article on the Yahoo breach-

http://arstechnica.com/security/2012/07/yahoo-service-hacked/

This sorta says it all:

QuoteHackers posted what appear to be login credentials for more than 453,000 user accounts that they said they retrieved in plaintext from an unidentified service on Yahoo.

Login credentials stored in plain text. Happens all too often.

Apparently there's some good news. From your link:

QuoteThe stolen data was contained in an "older file," and only about 5 percent of the exposed credentials were still valid on Yahoo.

Fortunately I updated my password a few weeks ago. Probably time to rotate it just to be sure, but truth be told, if someone really wants to have a share of my pallet of viagra, I'm only using about 80% of it a month anyway.
All that is gold does not glitter,
Not all those who wander are lost;
The old that is strong does not wither,
Deep roots are not reached by the frost.

LongBlade

Quote from: bayonetbrant on July 12, 2012, 01:23:43 PM
you can check to see if your info was part of the breach

http://labs.sucuri.net/?yahooleak

Grooby. Thanks.

xxxx@yahoo.com not found in leak.
All that is gold does not glitter,
Not all those who wander are lost;
The old that is strong does not wither,
Deep roots are not reached by the frost.

mirth

Quote from: LongBlade on July 12, 2012, 01:24:53 PM
Quote from: mirth on July 12, 2012, 01:17:16 PM
Here's another article on the Yahoo breach-

http://arstechnica.com/security/2012/07/yahoo-service-hacked/

This sorta says it all:

QuoteHackers posted what appear to be login credentials for more than 453,000 user accounts that they said they retrieved in plaintext from an unidentified service on Yahoo.

Login credentials stored in plain text. Happens all too often.

Apparently there's some good news. From your link:

QuoteThe stolen data was contained in an "older file," and only about 5 percent of the exposed credentials were still valid on Yahoo.

Fortunately I updated my password a few weeks ago. Probably time to rotate it just to be sure, but truth be told, if someone really wants to have a share of my pallet of viagra, I'm only using about 80% of it a month anyway.

Yeah you're talking about what, 23,000 valid accounts? That's pretty small by Yahoo! standards. This was definitely just meant as a wake up call.
"45 minutes of pooping Tribbles being juggled by a drunken Horta would be better than Season 1 of TNG." - SirAndrewD

"you don't look at the mantelpiece when you're poking the fire" - Bawb

"Can't 'un' until you 'pre', son." - Gus

LongBlade

Quote from: mirth on July 12, 2012, 01:18:11 PM
Quote from: LongBlade on July 12, 2012, 01:15:20 PM
Quote from: Barthheart on July 12, 2012, 01:14:05 PM
Where's the chicks?

Inside the Jagdpanther with me

Chicks dig the Jagdpanther. Especially the Saukopf mantlet.

If the tank's a-rockin' don't come a-knockin'!

I believe I have a new sig. (and, yes, I do know it's really a TD)
All that is gold does not glitter,
Not all those who wander are lost;
The old that is strong does not wither,
Deep roots are not reached by the frost.