Showing posts with label Ashley Madison. Show all posts
Showing posts with label Ashley Madison. Show all posts

Monday, 14 September 2015

Users Ashley Madison Had Often Name As Password


Users of the Ashley Madison website often used their username and password, so researchers have discovered. The group of researchers called Cynosure Prime showed last week that by some programming errors crack the password hashes of Ashley Madison are simple. At the hack of the cheaters website approximately 36 million password hashes were stolen.

Hashes to ensure that the user passwords are not immediately visible to an attacker in case the website is hacked. Ashley Madison used before a strong hashing algorithm, but by various programming errors hashes prove yet easy to crack. The researchers have cracked 11.7 million password hashes.

It shows that mainly weak and insecure passwords were used. So there were three million passwords of six characters and there were slightly less than 3 million, which consisted of eight males kara. The shortest password was cracked one character long. Nearly 10 million passwords only consisted of small letters or lowercase letters and numbers.

User Name

The researchers were also curious how many users are using their username and password. A total of 630 000 passwords were found that matched the user name. The investigators noted that the actual number is higher as possible, since there are obvious only obvious mutations were used. If there was more combinations of uppercase and lowercase letters sought was the true number is likely higher. The researchers argue that these passwords could be cracked too easily without programming errors found.

Striking Passwords

Instead of publishing a list of the Top 10 most common passwords, the researchers decided to create a collection of distinctive passwords. It is about passwords as allthegoodpasswordshavegone ',' youwillneverfindout ',' everynameitriedwastaken ',' goodguydoingthewrongthing ',' thisisagoodpassword 'and' correct horse battery staple ", known from the xkcd strip.

Thursday, 10 September 2015

Researchers Crack 11 Million Passwords Ashley Madison


Researchers have managed to crack more than 11 million passwords of Ashley Madison users, as they have announced today. The group of researchers called himself the cynosure Prime and examined the data that was stolen by the cheaters website. Attackers managed to steal gigabytes of data at Ashley Madison, including hashed passwords of users.

It involves a total of 36 million password hashes. Ashley Madison had the passwords are not stored in plain text, but in hashed form. This makes them not directly readable, but they can be cracked. For hashing the password had Ashley Madison the bcrypt algorithm used, and there was also a "salt-made 'use. This makes it much more difficult to crack password hashes. In a weaker algorithm, such as MD5, it is possible to try millions of password combinations per second. In the case of the gesalte bcrypt hashes came another researcher with his computer not go beyond 156 hashes per second. This investigator knew in five days 4000 passwords to crack.

It was therefore argued that the cracking of all Ashley Madison password hashes would last for centuries. That now seems not to be so. The researchers from Cynosure Prime investigated namely the second amount of data that was recently put online. In it they found information that helps them with the bcrypt hashed passwords could crack much faster. "Instead of cracking the slow bcrypt hashes, which is currently a hot topic, we decided to choose a more efficient approach and attack the MD5 tokens," the researchers said in their explanation.

The cheaters website appears to have used for reasons still unknown MD5 tokens. These tokens can be cracked much simpler than the bcrypt hashes. The information from the cracked tokens could then be used to crack the hashes bcrypt, she discovered. Since the researchers two weeks ago with their research, they began now more than 11.2 million bcrypt hashes cracked. In total there were in the stolen data over 15 million tokens.

Sunday, 23 August 2015

Hackers: Website Ashley Madison Was Poorly Protected


The security of Ashley Madison, the hacked website for adulterers, was far below par, say the hackers who carried out the hack. Last month the site was hacked, with data of some 32 million people, as well as all kinds of business data were captured.

The data this week were put partly online. There is now 30GB published on stolen data. In an interview with Vice Magazine let the hackers know they still have 300GB of emails from employees and documents from the internal network. Nor would they have held tens of thousands of photos of subscribers of the website and some chats and messages. One third of the images were photographs of male genitalia that they will not publish, which is also true for most emails from employees of the company.

The Impact Team, as hackers call themselves, denounce especially the absent protection from Ashley Madison. "We did our best to make the attack undetectable, but when we arrived it turned out that there was no security to get around." The security of a site by the hackers as "poor" circumscribed. "There was no monitoring. No security. The only thing was a segmented network." Furthermore, it was also easy to gain root access on the servers of Ashley Madison, as they note.Regarding the future, the hackers do not exclude that they also other sites, businesses and possibly corrupt politicians will hacking.

Subscribers Ashley Madison Extorted via E-mail



Several subscribers cheaters website Ashley Madison became the target of extortionists who threaten to inform their partner unless they pay an amount in bitcoin. Both American and New Zealand subscribers have received the email.

The email warns that the cost of a divorce lawyer if the partner comes behind the cheating, or anything revealing to have the data for consequences if someone is already in a separation procedure. It also warned of the reaction of family and friends as they discover that the person in question was active on Ashley Madison, so reporting CoinDesk and Stuff.

The extortionist then demands two bitcoins, what with the current exchange rate is 410 euros. How many subscribers have received the e-mail or run from the threat is unknown. Attackers managed last month to hack the website Ashley Madison this week and made ​​a part of the data publicly available. The media has already speculated that subscribers would be extorted possible.

Friday, 21 August 2015

Customer Data 600 In Stolen Data Ashley Madison



The personal data of users can be found in the stolen and published online database of Ashley Madison. These are e-mail addresses, mailing address and IP addresses, reports Yahoo! News that the stolen data analyzed.

A group of attackers managed to hack the website for cheaters last month and thereby made ​​gigabytes of data booty. It's about user profiles, as well as credit card transactions. In this final data set the data of the Dutch have been found. The data of 32 million users were on Monday put online. Tonight the attackers have again stolen data published reports Vice Magazine. This time it comes to 20GB of data, including e-mail inbox Noel Biderman, CEO of Avid Life Media, the parent company of Ashley Madison.

Wednesday, 19 August 2015

Email Addresses Ashley Madison Added To Search Engines



On the Internet, various search engines where the email addresses of subscribers AshleyMadison.com be added. In July, attackers were able to steal a database of user information from the site for cheaters.This database is two days ago put online.

This concerns data like email addresses, names and addresses, as well as GPS coordinates. Security expert Troy Hunt has the email addresses from the database to its search engine "haveibeenpwned.com added. The search engine, which since December 2013th is online, contains 220 million accounts that are captured at different hacks and made ​​public. Most accounts, 152 million, came from a break-in at Adobe.

In second place is Ashley Madison, with 30 million accounts. Other parties keep that data from 36 million accounts were stolen, but that was verified by some 24 million accounts, e-mail address. Internet users can be alerted via the search engine as their e-mail address found in a stolen database. Meanwhile were 5,000 subscribers Ashley Madison are alerted by the search engine, so let Hunt via Twitter know.

32 Million Users Data Ashley Madison Put Online


The attackers knew who last month at the Ashley Madison website to break in and loot that made ​​the data of millions of users have now put the data online. It involves account information and login details of around 32 million users of the website for cheaters, reports Wired.

In addition also published a list of seven years credit and payment transactions. This data consists of millions of payment transactions, including names, addresses, email addresses and amounts paid. The latter have been given four digits of the credit card. The stolen data is now distributed via Tor websites and torrent files. They can be downloaded from download sites like Rapidshare and Mega. The attackers had the data already published two days ago on Reddit, but it has now been picked up by the media.

The attackers demanded that Ashley Madison hacked the website and the website Established They were taken offline, otherwise they would make the data public. In a statement, the attackers set to Avid Life Media, the company behind Ashley Madison and Established Men, created thousands of fake profiles of women. The attackers The website also called a scam."Chances are good that you signed up for one of the largest websites for affairs, but have never had one." Victims of data theft getting the attackers advice to sue the company.

The database would be some 15,000 e-mail addresses ending in .gov and .mil. It is in this case to addresses used by the US military and government. In a statement enables Avid Life Media that does not involve hacktivism, but there is a crime.Meanwhile, the FBI would be involved in the investigation. According to the company, the attackers will eventually be caught.

Update

Security expert Robert Graham analyzed the stolen data and says that it is more than 36 million accounts. 28 million accounts are men, while five million women had registered for the website. The other accounts could not be determined.When analyzing the credit Graham came only men took against. In addition, there are 250,000 possible deleted accounts, since the password of it was removed. The account information includes full name, email address and password hash, but also data such as height and weight.

Also, mailing address and GPS coordinates were found in the data dump from 9,7GB. "I suspect that many players from creating a fake profile, but with an app that passed their real GPS coordinates," Graham says. The passwords are hashed with bcrypt. A stronger algorithm than MD5. Yet Graham expects hackers will succeed especially many weak passwords to "crack". Users with a strong password, however, would be safe.