Published On:Monday, July 16, 2012
Posted by asd
Firehost : Hackers publish 450,000 unencrypted Yahoo! passwords – SQL injections strike again
Yahoo! has become the latest brand to suffer a high profile security breach, with news that its Yahoo! Voice service, has been hacked by a group or individual calling themselves the D33Ds Company. Using very basic SQL injection techniques, the hackers were able to take more than 450,000 usernames and passwords as well as gain access to the company’s back office IT systems. It has subsequently published the hacked passwords – which were unencrypted – online.
Chris Hinkley, CISSP and senior security engineer at secure cloud hosting company, FireHost, has made the following comments:
“Yahoo! has fallen victim to a SQL injection attack, which in comparison to most of the tools in a hacker’s box, is a pretty straightforward and common method of attack. Just as surprising is that the company – which claims to have more than 600,000 contributors to its Yahoo Voice service – had not encrypted its user passwords. Though the hackers have described the incident as only a ‘wake-up call’, if organisations do not take more robust precautions, the next attack could be much more damaging.
“SQL injection attacks have become the method of choice among hackers seeking to exploit weaknesses in IT infrastructures, but with solutions readily available that are capable of blocking these threats, it’s frustrating that these attacks are still so successful. One way of beefing up security – whether that’s by strengthening perimeter defences or deploying hashing or encryption – is by moving operations to the cloud. While the cloud has traditionally been viewed as a risk to enterprise security, today’s new wave of cloud firms have designed their platforms to protect against even the most sophisticated of attacks. If recent media headlines are anything to go by, this is something that enterprises are really struggling with.
"With competitions like the upcoming Crack Me If You Can at DEFCON 20 later this month, password cracking techniques are only going to get more efficient. One of the most troubling trends we're seeing over the last few high profile breaches, is that organisations are not taking adequate steps to protect user information."
Source: CLICK HERE
