ukwirednews
Technology
Yahoo investigating exposure of 400,000 passwords
Published: 12th Jul 2012 13:12:45
Web giant Yahoo has confirmed it is investigating a breach of its system which may have exposed 400,000 user IDs.
US security firm Trustedsec said the attack appeared to have originated from servers connected to Yahoo Voices, a user-generated section of the site.
It said that hacking group D33DS had claimed to be behind the attack.
Hours after the attack came to light, Yahoo had not put a warning on its site.
In a statement Yahoo said: "We are currently investigating the claims of a compromise of Yahoo! user IDs," adding that it encouraged users to "change their passwords on a regular basis".
She said it was unclear which part of the network was affected. Initially a Yahoo spokesman told the BBC that the problem had originated at Yahoo Voice, its IP telephony service.
The document which gives details of the hack does not make clear which Yahoo service was targeted.
According to US security firm Trustedsec, the compromised Yahoo passwords were associated with a variety of email addresses including those from yahoo.com, gmail.com and aol.com.
It said that hackers used a well-established technique known as SQL injection to extract the sensitive information from the database.
"The most alarming part of the entire story was the fact that the passwords were stored entirely unencrypted," the security firm said in its blog.
Initial analysis by security firm Impervia suggests that the compromised database may have contained some private data as well including names, addresses including postcode, phone numbers and dates of birth.
Meanwhile social network Formspring has disabled nearly 30 million passwords following a separate attack.
It said it was a precautionary move after 420,000 passwords showed up on a security forum.
Formspring, which launched in 2009 as a crowd-powered question-and-answer site, has asked users to reset their passwords.
In a blog post it confirmed that a breach had occurred after someone hacked into one of the San Francisco-based company's servers.
A spokeswoman said it had been alerted on Monday that some 420,000 encrypted passwords had shown up on a security forum which she refused to name because she did not want to draw attention to it.
Encrypted passwords aren't immediately useable, although they can sometimes be decoded by a clever attacker.
Harvard Citation
BBC News, 2012. Yahoo investigating exposure of 400,000 passwords. [Online] (Updated 12 Jul 2012)Available at: http://www.ukwirednews.com/news.php/1440196-Yahoo-investigating-exposure-of-400-000-passwords [Accessed 24th May 2013]
Latest News
-
At 19:36:32 in England
M4 closed eastbound after second Severn crossing crash
The M4 motorway has been closed eastbound because of a multi-vehicle crash on the second Severn Crossing.... -
At 19:34:50 in England
London Bridge Station evacuated over police incident
London Bridge railway station has reopened after being evacuated over reports of a man with a weapon at the station, police have said.... -
At 19:29:30 in England
Alps crash passengers to sue coach firm for damages
Some of the passengers injured in a fatal crash in the French Alps plan to sue the coach operator.... -
At 19:16:02 in England
Tiger attacks woman at South Lakes Wild Animal Park
A woman zoo worker has been seriously injured by a tiger in Cumbria.... -
At 19:00:11 in England
More time for Bristol's controlled parking zone talks
Residents and businesses in Bristol are being given more time to have their say over plans to introduce a residents' parking scheme ove... -
At 18:53:52 in Headlines
Ecuador President Rafael Correa sworn in for third term
Ecuador's President, Rafael Correa, has been sworn into office for an unprecedented third term in the capital, Quito.... -
At 18:51:27 in England
M6 in Warwickshire closed in both directions
The M6 has been closed in both directions in Warwickshire because of what police have described as a "suspicious vehicle".... -
At 18:43:18 in Northern Ireland
Former church repossessed by Nama
A deconsecrated Methodist church in south Belfast has been repossessed by the Irish government's National Asset Management Agency (NAMA... -
At 18:32:23 in England
Shakespeare's property deed signature to go on display
A signature by William Shakespeare dating back about 400 years will go on display at an exhibition at the London Metropolitan Archives.... -
At 18:30:15 in Headlines
Five climbers are feared dead on Nepal's Kanchenjunga
Five climbers who went missing earlier this week on Mount Kanchenjunga in Nepal are feared dead, officials say. ...
News In Other Categories
-
M4 closed eastbound after second Severn crossing crash
The M4 motorway has been closed eastbound because of a multi-vehicle crash on the second Severn Crossing.... -
Trafalgar Square marks 350 years of West End theatre
The Phantom of the Opera and Les Miserables have been announced as shows performing free songs to the public, to mark 350 years of West End ... -
Trafalgar Square marks 350 years of West End theatre
The Phantom of the Opera and Les Miserables have been announced as shows performing free songs to the public, to mark 350 years of West End ... -
Bloodhound diary: Rolls of advice
A British team is developing a car that will be capable of reaching 1,000mph (1,610km/h). Powered by a rocket bolted to a Eurofighter-Typho... -
Big rise in volunteers for medical trials
The number of patients taking part in clinical trials in England has trebled in five years. ... -
M4 closed eastbound after second Severn crossing crash
The M4 motorway has been closed eastbound because of a multi-vehicle crash on the second Severn Crossing....



