Showing posts with label Married Dating Site. Show all posts
Showing posts with label Married Dating Site. Show all posts

Sunday, 23 August 2015

Hackers: Website Ashley Madison Was Poorly Protected


The security of Ashley Madison, the hacked website for adulterers, was far below par, say the hackers who carried out the hack. Last month the site was hacked, with data of some 32 million people, as well as all kinds of business data were captured.

The data this week were put partly online. There is now 30GB published on stolen data. In an interview with Vice Magazine let the hackers know they still have 300GB of emails from employees and documents from the internal network. Nor would they have held tens of thousands of photos of subscribers of the website and some chats and messages. One third of the images were photographs of male genitalia that they will not publish, which is also true for most emails from employees of the company.

The Impact Team, as hackers call themselves, denounce especially the absent protection from Ashley Madison. "We did our best to make the attack undetectable, but when we arrived it turned out that there was no security to get around." The security of a site by the hackers as "poor" circumscribed. "There was no monitoring. No security. The only thing was a segmented network." Furthermore, it was also easy to gain root access on the servers of Ashley Madison, as they note.Regarding the future, the hackers do not exclude that they also other sites, businesses and possibly corrupt politicians will hacking.

Friday, 21 August 2015

Customer Data 600 In Stolen Data Ashley Madison



The personal data of users can be found in the stolen and published online database of Ashley Madison. These are e-mail addresses, mailing address and IP addresses, reports Yahoo! News that the stolen data analyzed.

A group of attackers managed to hack the website for cheaters last month and thereby made ​​gigabytes of data booty. It's about user profiles, as well as credit card transactions. In this final data set the data of the Dutch have been found. The data of 32 million users were on Monday put online. Tonight the attackers have again stolen data published reports Vice Magazine. This time it comes to 20GB of data, including e-mail inbox Noel Biderman, CEO of Avid Life Media, the parent company of Ashley Madison.

Wednesday, 19 August 2015

32 Million Users Data Ashley Madison Put Online


The attackers knew who last month at the Ashley Madison website to break in and loot that made ​​the data of millions of users have now put the data online. It involves account information and login details of around 32 million users of the website for cheaters, reports Wired.

In addition also published a list of seven years credit and payment transactions. This data consists of millions of payment transactions, including names, addresses, email addresses and amounts paid. The latter have been given four digits of the credit card. The stolen data is now distributed via Tor websites and torrent files. They can be downloaded from download sites like Rapidshare and Mega. The attackers had the data already published two days ago on Reddit, but it has now been picked up by the media.

The attackers demanded that Ashley Madison hacked the website and the website Established They were taken offline, otherwise they would make the data public. In a statement, the attackers set to Avid Life Media, the company behind Ashley Madison and Established Men, created thousands of fake profiles of women. The attackers The website also called a scam."Chances are good that you signed up for one of the largest websites for affairs, but have never had one." Victims of data theft getting the attackers advice to sue the company.

The database would be some 15,000 e-mail addresses ending in .gov and .mil. It is in this case to addresses used by the US military and government. In a statement enables Avid Life Media that does not involve hacktivism, but there is a crime.Meanwhile, the FBI would be involved in the investigation. According to the company, the attackers will eventually be caught.

Update

Security expert Robert Graham analyzed the stolen data and says that it is more than 36 million accounts. 28 million accounts are men, while five million women had registered for the website. The other accounts could not be determined.When analyzing the credit Graham came only men took against. In addition, there are 250,000 possible deleted accounts, since the password of it was removed. The account information includes full name, email address and password hash, but also data such as height and weight.

Also, mailing address and GPS coordinates were found in the data dump from 9,7GB. "I suspect that many players from creating a fake profile, but with an app that passed their real GPS coordinates," Graham says. The passwords are hashed with bcrypt. A stronger algorithm than MD5. Yet Graham expects hackers will succeed especially many weak passwords to "crack". Users with a strong password, however, would be safe.