Over 25 Million Accounts Stolen After Mail.ru Forums Hacked (zdnet.com)
An anonymous reader writes: Over 25 million accounts associated with forums hosted by Russian internet giant Mail.ru have been stolen by hackers. Two hackers carried out attacks on three separate game-related forums in July and August. One forum alone accounted for almost half of the breached data -- a little under 13 million records; the other two forums making up over 12 million records. The databases were stolen in early August, according to breach notification site LeakedSource.com, which obtained a copy of the databases. The hackers' names aren't known, but used known SQL injection vulnerabilities found in older vBulletin forum software to get access to the databases. An analysis of the breached data showed that hackers took 12.8 million accounts from cfire.mail.ru; a total of 8.9 million records from parapa.mail.ru, and 3.2 million accounts from tanks.mail.ru. The hackers were able to obtain usernames, email addresses, scrambled passwords, and birthdays.
Must have been running some lousy Open sores software. Those things are always getting infected.
Russia did it !
Yours In The Pentagon,
K. Trout
The hackers were able to obtain usernames, email addresses, scrambled passwords, and birthdays.
So they have usernames (made up), email addresses (like I have on my business card), scrambled passwords (not even sure if this matters), and birthdays (not really something that many keep private anyway). I wouldn't care if any of this were taken from me, even if it were my gmail account.
Politics; n. : A religion whereby man is god.
DNC nerd goons looking for retribution ...
is that you Kilgore?
May the lies we live by make us strong, healthy, happy and wise - Kurt Vonnegut.
By doing this, they admit they're doing this.
I bet it was again those evil russian hack-
Oh wait...
In Soviet Russia ... you
The vast majority of the accounts probably were fake accounts used by spammers. Oh, well...
Maybe it was the DNC thinking payback was fair play?
I am little bit confused about the subject matter
Mukter
owner of http://pickbestfishoil.com/
A method to detect and prevent SQL injection attack
SQL injection refers to an injection attack wherein an attacker can execute malicious SQL statements that control a web application’s database server. Since an SQL injection vulnerability could possibly affect any website or web application that makes use of an SQL-based database. SQL injection can provide an attacker with unauthorized access to sensitive data including, customer data, personally identifiable information, trade secrets, intellectual property and other sensitive information.
http://amzn.to/2bOarSo
Be aware that emails from the following parapa addresses may be malicious:
sunnyfunny@mail.ru
katykat@mail.ru
joechin@mail.ru
Probably one who wants to date Debbie Wasserman Schultz
Seriously, do we need an icon for vBulletin now? That's 4 stories in less than 2 weeks about major forums having their information leaked via known vBulletin exploits. It sounds like some people (maybe the same ones each time, maybe not) are just going around to all the major forums that run vBulletin and seeing if they're running an older version with the known vulnerability. Surprise, surprise - most forums haven't bothered to upgrade their vBulletin software. If we're going to keep seeing this story every time there's another vBulletin security exploit, we may as well have a specific tag for it, because I'm guessing it's going to go on for a while longer.
See also, little Bobby Tables.
"over 25 million spammer accounts stolen" the amount of spam i get from mail.ru .. i think 90% of the emails they have are created by bots to spam.
It's not a typo if you understood the meaning!