5 percent of stolen passwords were valid: Yahoo!

Powered by SC Magazine
 

No word on why passwords weren't encrypted.

Yahoo! has claimed only five percent of the 450,000 passwords stolen from its Voices service yesterday remain valid.

The company is disabling passwords and notifying companies whose domains were used by staff to register for the service.

The credentials were published in clear text in what the company claimed was an "older file".

However, Yahoo! did not respond to questions from SC about whether they were initially encrypted or why they were stored in clear text.

The group dubbed 'd33ds' claimed responsibility for the hack. Security researchers said the credentials were stolen from Yahoo.com subdomain dbb1.ac.bf1.yahoo.com.

Yahoo! said in a statement that it took "security very seriously" and invested "heavily in protective measures".

"We confirm that an older file from Yahoo! Contributor Network (previously Associated Content) containing approximately 450,000 Yahoo! and other company users names and passwords was compromised on July 11," a spokesperson said in a statement to SC.

Content from the Contributor Network was published on Yahoo! Voices among other sites.

"We are taking immediate action by fixing the vulnerability that led to the disclosure of this data, changing the passwords of the affected Yahoo! users and notifying the companies whose users accounts may have been compromised," the company said.

"We apologise to all affected users."

TrustedSec said the breached appeared to be a union-based SQL injection attack to extract the sensitive information from the database. Those attacks could force vulnerable databases to regurgitate large amounts of information by issuing crafted requests.

Users of Yahoo! Voices could validate their exposure to the breach by entering their email addresses into a tool created by Securi's Daniel Cid.

Copyright © SC Magazine, Australia


5 percent of stolen passwords were valid: Yahoo!
 
 
 
Top Stories
The iTnews Benchmark Awards
Meet the best of the best.
 
Telstra hands over copper, HFC in new $11bn NBN deal
Value of 2011 deal remains intact.
 
Photos: iTnews Benchmark 2015 finalists revealed
Awards alumni gather to celebrate.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  4%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  6%
TOTAL VOTES: 1745

Vote
Do you support the abolition of the Office of the Information Commissioner?