 antdudeA Ninja AntPremium,VIP join:2001-03-25 United State kudos:4 | Nearly Half a Million Yahoo Passwords Leaked »it.slashdot.org/story/12/07/12/1···s-leaked |
|
 caffeinatorComing soon to a cup near you..Premium join:2005-01-16 WA, USA kudos:4 | Apparently hacked via Voices, a Yahoo social networking news service, go figure.
I changed mine just in case, can't hurt eh? |
|
 siljalineI'm lovin' that double widePremium join:2002-10-12 Montreal, QC kudos:17 Reviews:
·Bell Sympatico
| reply to antdude • Also spotted on Tech Radar this morning:
From: Ubergizmo From: The Verge From: SecurityWeek
First order of business would to at least overview your whole account and at least change the password, at a minimum. |
|
|
|
 | reply to antdude here is a tool where people supposedly can check to see if their accounts were included in the leaded data:
»labs.sucuri.net/?yahooleak
i checked all of my email addresses.. the tool reported that none of them were included in the leaked data..
i had already changed my passwords for my yahoo accounts but i wondered if the new passwords wouldn't be captured, too.. the news articles say that yahoo is still working on the problem so it hasn't been fixed, yet, which means that my new passwords could be captured the same as the old ones.. uhg! |
|
 antdudeA Ninja AntPremium,VIP join:2001-03-25 United State kudos:4 Reviews:
·RoadRunner Cable
| reply to caffeinator said by caffeinator:Apparently hacked via Voices, a Yahoo social networking news service, go figure.
I changed mine just in case, can't hurt eh? Does it use the same password/account as global Yahoo! address or are they separate? -- Ant @ »antfarm.ma.cx and »aqfl.net. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer |
|
 antdudeA Ninja AntPremium,VIP join:2001-03-25 United State kudos:4 | reply to antdude »betanews.com/2012/07/12/yahoo-ha···assword/ for the password patterns. |
|
 caffeinatorComing soon to a cup near you..Premium join:2005-01-16 WA, USA kudos:4 Reviews:
·CenturyLink
1 edit | reply to antdude Something is weird here, according to this: »blog.sucuri.net/2012/07/analysis···sed.html
It's not just yahoo emails in the dump, but addys used for Yahoo Voices. (it's an eHow publishing platform I think)
quote: comments:
Virtual Copy Actually, the leak is of Yahoo! Voices, formerly Associated Content and of the Yahoo! Contributor Network. None of us have been officially notified as of yet by Yahoo staff.
Matt Busse As Virtual Copy notes in these comments, Yahoo Voices / the Yahoo Contributor Network, from which the leak came, had acquired Associated Content, a user-contributed-articles site similar to eHow.com. That might explain why 101 passwords were the word associated (and perhaps why 164 were writer), and might also explain why so few have the word yahoo in them.
So, if I'm reading this right, it's 400K+ misc. addy's and not just yahoo emails? I've never used that thing, so it makes more sense why I wasn't effected. --
My 9/11 Tribute..online since 9/14/01 Need an Avatar? Check out Wafen's Avatar Pages |
|
 sivranOpera convertPremium join:2003-09-15 Arlington, TX kudos:1 | reply to redwolfe_98 said by redwolfe_98:here is a tool where people supposedly can check to see if their accounts were included in the leaded data:
»labs.sucuri.net/?yahooleak
i checked all of my email addresses.. the tool reported that none of them were included in the leaked data..
Thanks for the link. Checked a couple of my ancient yahoo accounts, plus my Dad's, none of them showed up. Good to know.
Still...I think I might want to have Dad change his password, just to be sure. -- Think Outside the Fox. |
|
 jaykaykay4 Ever YoungPremium,MVM join:2000-04-13 Scottsdale, AZ kudos:22 | reply to redwolfe_98 Thank you. I just checked and we're OK. Still, a change might be the thing to do. Can't hurt. |
|
 planet join:2001-11-05 Oz kudos:1 1 edit | Does the leak effect yahoo email or just the Yahoo Voices accounts?
Edit: here's another way to check if your user name/pw was leaked. List of the user names leaked: »dazzlepod.com/yahoo/ |
|
 Sindows 7 join:2006-09-13 Chilliwack, BC kudos:2 | reply to antdude quote: but it wasn't just credentials for Yahoo, but also Gmail, AOL, Comcast, Hotmail, MSN, SBC Global, BellSouth, Verizon and Live.com as well
|
|
 siljalineI'm lovin' that double widePremium join:2002-10-12 Montreal, QC kudos:17 Reviews:
·Bell Sympatico
| reply to antdude Update: Yahoo's massive data breach includes Gmail, Hotmail, Comcast user names and passwords 
quote: Yahoo today confirmed a breach of its network, saying that not only Yahoo user names and passwords were stolen yesterday but also "other company users names and passwords." Yahoo said the data stolen is related to "an older file from Yahoo! Contributor Network (previously Associated Content)," the Web farm and multimedia content company it acquired two years ago for $100 million.
That Yahoo file of unspecified vintage contained about 400,000 Yahoo and other company users names and passwords that was dumped on the Internet included many associated with Google Gmail, Microsoft Hotmail, and AOL, Comcast and MSN accounts (see list below). Yahoo, which was not immediately available to discuss the data breach, said in a statement that when it comes to the Yahoo accounts, "less than 5% of the Yahoo! Accounts had valid passwords."
More |
|
 | reply to antdude _____________________
Technology news websites including CNET, Ars Technica, and Mashable identified the hackers behind the attack as a little-known outfit calling itself the D33D Company. The group was quoted as saying it had stolen the unencrypted passwords using an SQL injection , the name given to a commonly used attack in which hackers use rogue commands to extract data from vulnerable websites.
"We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call," the group was quoted as saying.
»www.philly.com/philly/business/2···rds.html |
|
 SnowymIRC unix.ro UnderNetPremium join:2003-04-05 Kailua, HI kudos:6 | reply to antdude The group that took the data has mirrored the list of accounts that were compromised here. [Mirrors - Offical] h ttp://74.208.161.170:81/yahoo-disclosure.tar.gz |
|
 vaxvmsferroequine fanPremium join:2005-03-01 Wormtown | reply to antdude I wonder what percentage of all the Yahoo accounts (~500,000 of ~???) had passwords leaked? -- Of course I can keep secrets. It's the people I tell them to that can't keep them. |
|
 scross join:2002-09-13 Cordova, TN | reply to antdude So, given the prevalence of the top 10 or top 100 (or whatever) passwords, shouldn't these as a matter of policy be "forbidden" passwords, with said list being updated on a regular basis? I understand that this might be a bit of a technical challenge, for various reasons. |
|
 caffeinatorComing soon to a cup near you..Premium join:2005-01-16 WA, USA kudos:4 Reviews:
·CenturyLink
| reply to The Snowman said by The Snowman: _____________________
Technology news websites including CNET, Ars Technica, and Mashable identified the hackers behind the attack as a little-known outfit calling itself the D33D Company. The group was quoted as saying it had stolen the unencrypted passwords using an SQL injection , the name given to a commonly used attack in which hackers use rogue commands to extract data from vulnerable websites. Obligatory XKCD... 
 --
My 9/11 Tribute..online since 9/14/01 Need an Avatar? Check out Wafen's Avatar Pages |
|
 NormanSPremium,MVM join:2001-02-14 San Jose, CA kudos:9 Reviews:
·SONIC.NET
·Pacific Bell - SBC
| reply to antdude said by antdude:Does it use the same password/account as global Yahoo! address or are they separate? »Re: E-Mail "Contact List" Hack
Looks global. -- Norman ~Oh Lord, why have you come ~To Konnyu, with the Lion and the Drum |
|
 | reply to antdude Does this affect people who only have a free Yahoo email account and have never used Voices? |
|
 jabarnutLight Years AwayPremium,MVM join:2005-01-22 Galaxy M31 kudos:2 | reply to antdude said by redwolfe_98:here is a tool where people supposedly can check to see if their accounts were included in the leaded data:
»labs.sucuri.net/?yahooleak
i checked all of my email addresses.. the tool reported that none of them were included in the leaked data.. ..... Just call me silly and overly paranoid, but is it a real good idea for everyone to be typing all of their legit email addresses into a box and sending it over an unencrypted connection? I'm sure no harm, but I kind of get a kick out of that site when we're talking about a 'security' breach here. -- I had a life once.....now I have a Computer and a Modem. |
|