Showing posts with label Troy Hunt. Show all posts
Showing posts with label Troy Hunt. Show all posts

Sunday, 29 November 2015

Major Security Flaws In Hacked Toy Manufacturer VTech


The Chinese manufacturer of educational toys VTech where recently the data of 4.8 million adults and 200,000 children were stolen customer data had not properly secured, according to the Australian security expert Troy Hunt that captured customer data analyzed.

Recently managed to get an attacker access to the customer database and approached Vice Magazine. The journalist of the magazine then contacted Hunt to verify the data. Hunt was sent several files, the largest of which was 1,7GB. This file, called parent.csv, he found the details of 4.8 million people. It was e-mail addresses, names, IP address, mailing address and encrypted passwords. The password proved to be hashed with the MD5 algorithm. It is therefore not directly readable, but MD5 has long been considered unsafe because it is easy to 'crack'. This allows an attacker can still retrieve the password.

VTech had not taken additional measures to protect the passwords, such as the use of "salts" and "stretching". However, it is not the only security problem, says Hunt. As the website does not use SSL, so all communications, including passwords, unencrypted occurs. There is no cryptographic protection of sensitive data, the expert noted. The website appears to provide a SQL statement back at login. The attacker said that he had come in via SQL injection, a problem that has been known since 1998 but is ignored by some companies still. Finally Hunt criticizes the extensive use of Flash on the website of VTech.

The expert also manages the website Have I Been Pwned, where Internet users can check whether they appear in the database of hacked websites. The data of the 4.8 million adults from the database of VTech here are now added. That does not apply to the data of 227 000 children who also were in the stolen data. Hunt has not been added. VTech has confirmed a burglary, but do not know how the attacker managed to get inside.

Tuesday, 13 October 2015

Expert: Precautions LastPass Users After Purchase LogMeIn



Last Friday it was announced that the popular online password manager LastPass for an amount of $ 125 million was taken, but the new owner LogMeIn has caused some users worry. Reported that the Australian security expert Troy Hunt.

LogMeIn is a company that offers software that allows remote access to computers can be obtained. The company's image is not flawless. So let LogMeIn in 2011 that LogMeIn would always be free. Last year, however, the company announced the end of LogMeIn Free on. Another point is that the LogMeIn software is often used by telephone scammers posing as Microsoft employees. In early 2012 Hunt attention to the issue. "Unfortunately, three years later LogMeIn continues to be the preferred software of these crooks," he tells.

According to Hunt many people are also concerned about the direction that LastPass for the acquisition will go up. "Even though they say that the password manager remains independent and is not influenced, they now fall within a broader business vision and LogMeIn will influence the direction of LastPass," said security expert. He therefore anxious for LastPass users a roadmap put online that explains how simple of LastPass can be switched to 1Password, another popular password manager.

Wednesday, 19 August 2015

Email Addresses Ashley Madison Added To Search Engines



On the Internet, various search engines where the email addresses of subscribers AshleyMadison.com be added. In July, attackers were able to steal a database of user information from the site for cheaters.This database is two days ago put online.

This concerns data like email addresses, names and addresses, as well as GPS coordinates. Security expert Troy Hunt has the email addresses from the database to its search engine "haveibeenpwned.com added. The search engine, which since December 2013th is online, contains 220 million accounts that are captured at different hacks and made ​​public. Most accounts, 152 million, came from a break-in at Adobe.

In second place is Ashley Madison, with 30 million accounts. Other parties keep that data from 36 million accounts were stolen, but that was verified by some 24 million accounts, e-mail address. Internet users can be alerted via the search engine as their e-mail address found in a stolen database. Meanwhile were 5,000 subscribers Ashley Madison are alerted by the search engine, so let Hunt via Twitter know.

Sunday, 24 May 2015

Date 3.9 Million Members In Adult Dating Search Engine


This week that attackers had managed to steal a database of adult dating site Adult FriendFinder containing the personal information of 3.9 million members . The data were then made ​​public. Security expert Troy Hunt has this data now added to his " Haveibeenpwned.com "search engine.

For a variety of large data breaches that occurred in recent years, such as those from Adobe, with data from tens of millions of users were captured, Hunt decided to create a website that contains information from hacked databases. Internet users can search through this search engine or even their e-mail address is being stolen from such intrusion. The search engine now contains the details of all known hacked businesses and 183 million accounts.

The data come from burglaries at Adobe, Mail.ru , Bitcoin Security Forum, Snap Chat, Stratfor, Gawker, Forbes, Yahoo, Sony and other companies. Users can enter their email address on the website and get that message right away or they are listed in one of the stolen databases. Internet users also can sign up so they get automatically notified if their email address is listed in a stolen database that is added to the search engine in the future.

Tuesday, 7 April 2015

Researcher: Phone Scammers Are Not Innocent


The phone scammers who call people at home and pretend to be Microsoft employees are no innocent call center staff who read a script. This enables the Australian researcher Troy Hunt. He made ​​in 2012 in a video which showed how to work the scammers.


The scammers claim that there is a problem with your computer, and then try to let the user install software so they gain control of the system. Eventually, the so-called problems are solved and the user should pay. Recently warned Microsoft for this type of scam. Hunt was not called for some time, but recently was approached twice on the same day and took two calls on.

In one of the conversations he is at the end insulted and abused by crook. Therefore, there is according to the researcher no doubt that this was going to be innocent call center staff, but these people know very well what they are doing. "These are just annoying people and I have no doubt that they are complicit in these deceptive and illegal activities," said Hunt.