top banner 2

  The Security Universe at Your Fingertips:
     Attend iSecurity, Thursday, June 13, 2013, 10:00 am - 4:00 pm ETwww.isecuritytradeshow.com

Cyber Security
Cyber Security -- Hacking

453,000 Yahoo Voice Passwords Leaked

In the latest in a string of password leaks, a hacker or hacking group calling itself “DD3Ds Company” leaked what it said were plaintext passwords for 453,492 Yahoo accounts, calling the attack a “wake-up call,” not a threat, according to an article from Information Week.

DD3Ds also released more than 2,700 database table or column names, as well as 298 MySQL variables. The groups said it obtained the data by executing a SQL injection attack against Yahoo Voice, a Yahoo subdomain purchased in 2010 from online call company Associated Content, the article says.

In a note included in the password dump, the hackers say: “We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat. … There have been many security holes exploited in webservers belonging to Yahoo! Inc. that have caused far greater damage than our disclosure. Please do not take them lightly. The subdomain and vulnerable parameters have not been posted to avoid further damage.”

A Yahoo spokesman said that the company is currently investigating the alleged password leak.

This is only one of many recent password leaks from notable personal and social networking sites, such as eHarmony and LinkedIn.

According to DD3Ds, Yahoo was not even hashing its passwords – the process in which a normal, typed password is run through an encryption algorithm to produce a digital fingerprint of the password which cannot easily be traced back to the original word.

Plus, if DD3Ds is correct in stating that Yahoo was storing passwords in plaintext without encryption, privacy experts foresee FTC sanctions, the article says.  

 

For more information on how to protect your business or organization from hackers and data breaches, read this week's Security eNewsletter article: 5 Steps to Protecting Data in Small- and Medium-Sized Businesses.

Did you enjoy this article? Click here to subscribe to Security Magazine. 

You must login or register in order to post a comment.

Multimedia

Videos

Image Galleries

Podcasts

Changing the Perception of Security in Healthcare

In this Security exclusive, Gail Lenehan, President of the Emergency Nurses Association, and Bryan Warren, President of the International Association for Healthcare Security & Safety, discuss the reputation security has in the healthcare industry and its effect on workplace violence.

More Podcasts

THE MAGAZINE

Security Magazine

2013 May SEC

2013 May

This month in Security, discover how security can span the globe with our special feature on Securing the Global Enterprise. Also, determine how to do business in conflict zones, learn the top 11 errors in emergency planning, get smart about smartphones and study the consequences of performing temporary security for temporary employees.

Table Of Contents Subscribe

Situational Awareness

What is your level of certainty that your video network is performing all the time, meaning cameras are working and video is being recorded and is available for playback?
View Results Poll Archive

THE SECURITY STORE

comptiahighriseproductphoto
CompTIA Security+ Certification Study Guide
CompTIA's Security+ certification is a globally-recognized, vendor neutral exam that has helped over 60,000 IT professionals reach further and higher in their careers. The current Security+ exam (SY0-201) focuses more on being able to deal with security issues rather than just identifying them.
More Products

Clear Seas Research

Clear Seas ResearchWith access to over one million professionals and more than 60 industry-specific publications,Clear Seas Research offers relevant insights from those who know your industry best. Let us customize a market research solution that exceeds your marketing goals.

Vertical Sector Focus: Critical Infrastructures

criticalhomepagethumbFrom terrorism to vandalism, it’s preparedness, response, training and partnerships. Learn about some of the critical security issues facing this sector.

Visit the Critical Infrastructure page to read more.  

STAY CONNECTED

Facebook 40px 2-12-13 Twitter logo 40px 2-12-13  YouTube logo 40px 2-12-13  LinkedIn logo 40px 2-12-13