Yahoo hack yields 435,000 passwords

woofy

The Master of Disaster
Staff member
Yahoo has kicked off an investigation into a hack and extract operation of its Voices website that apparently compromised over 435,000 accounts via an SQL Injection attack.




"A recent post over 400,000 plus accounts that have clear text passwords were posted online. The passwords contained a wide variety of email addresses including those from yahoo.com, gmail.com, aol.com, and much more," TrustedSec researchers confirmed in an official post.




matrixsystemfailure.jpg


"The affected website was only named as a subdomain of yahoo.com however digging through and searching for the hostname, the attacker forgot to remove the hostname 'dbb1.ac.bf1.yahoo.com.' Looking through a variety of sources, it appears that the compromised server was likely Yahoo! Voices which was formally known as Associated Content."




According to TrustedSec, the data was stored in "completely unencrypted" files.
As such, the full 400,000+ usernames and passwords are now public after being posted by a hacker group known as "D33DS Company."



"We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat," the group wrote in an online communiqu
 
Back
Top