Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This should come as no surprise, but it still sucks big-time: thousands of people who downloaded a random, very popular app called WiFi Finder found that it got handsy with users’ own home Wi-Fi, uploading their network passwords to a database full of 2 million passwords that was found exposed and unprotected online. . The leaked database was discovered by Sanyam Jain, a security researcher and a member of the GDI Foundation who reported his find to TechCrunch. Jain and TechCrunch’s Zack Whittaker spent more than two weeks fruitlessly trying to contact the developer, who they believe is based in China. The link for this article located at NakedSecurity is no longer available. . A popular app faced criticism after exposing the private Wi-Fi passwords of around 2 million users, raising serious privacy concerns and stressing security flaws. WiFi Finder, Password Compromise, User Data Breach, Security Flaw. . Brittany Day
42 Million Passwords . The data was found on the same server where the hacked data from some other big heists was stored (Adobe/PR Newswire/NW3C etc). And to make it even worse, at least 10% of the users (which itself is over 4 million) use absolutely terrible passwords The link for this article located at Darknet is no longer available. . Delve into the shocking Cupid Media breach that exposed 42 million passwords in unencrypted form, jeopardizing user information and safety.. Password Exposure, User Data, Cybersecurity Threat, Data Compromise. . LinuxSecurity.com Team
As 450,000 passwords exposed, Yahoo fails security 101 -- If it wasn't clear before, it certainly is now: Your username and password are almost impossible to keep safe.. Nearly 443,000 e-mail addresses and passwords for a Yahoo site were exposed late Wednesday. The impact stretched beyond Yahoo because the site allowed users to log in with credentials from other sites -- which meant that user names and passwords for Yahoo (YHOO, Fortune 500), Google's (GOOG, Fortune 500) Gmail, Microsoft's (MSFT, Fortune 500) Hotmail, AOL (AOL) and many other e-mail hosts were among those posted publicly on a hacker forum. The link for this article located at CNN Money is no longer available. . Nearly 443,000 e-mail addresses and passwords for a Yahoo site were exposed late Wednesday. The impa. passwords, exposed, yahoo, fails, security, wasn't, clear, certainly. . LinuxSecurity.com Team
Twitter is investigating an apparent data breach that resulted in more than 50,000 user names and passwords being posted to the Internet. The data was posted across five pages (one, two, three, four, five) on Pastebin, a favorite site for hackers to post their ill-gotten gains. Ordinarily, when large files are involved, data thieves "tease" their exploits at the site and include a link to a site, like BitTorrent, that supports large file downloads. The maximum file size for Pastebin is 512KB.. Twitter is downplaying the leak because much of the information posted to Pastebin appears to be garbage. There are some 20,000 duplicates, many of the accounts belong to suspended spammers, and some of it consists of "unlinked" information, information where the user name doesn't correspond to the password paired with it. The link for this article located at InfoWorld is no longer available. . Social media giant Twitter is looking into a security incident that led to the leak of 50,000 user accounts, including their usernames and passwords shared on the internet.. Twitter Breach, User Credentials, Data Exposure. . LinuxSecurity.com Team
It'll take the London region's public school board more than three weeks to fix a privacy breach created in about an hour - way too long for a basic security feature, says one technology specialist.. London police criminally charged a 15-year-old self-described hacker with breaking into the Thames Valley District school board's website and exposing the passwords of 27,000 high school students on Oct. 23. It was the largest security breach in the board's history. Ordinarily, conviction on the four charges the youth faces could lead to as many as 10 years in prison, depending how the Crown proceeds. The link for this article located at Toronto Sun is no longer available. . London police criminally charged a 15-year-old self-described hacker with breaking into the Thames V. it'll, london, region's, public, school, board, three, weeks, privacy, breach. . LinuxSecurity.com Team
An unknown Christian dating site was recently hacked and whoever responsible managed to gain access to a list of email addresses and passwords. It. We initially managed to get hold of one the original txt files complete with email addresses and passwords, but we The link for this article located at TheNextWeb is no longer available. . We initially managed to get hold of one the original txt files complete with email addresses and pas. unknown, christian, dating, recently, hacked, whoever, responsible, managed. . LinuxSecurity.com Team
On the eve of the Black Hat security conference, crackers published a comprehensive text document in the underground magazine Zero for Owned (ZF0), containing masses of emails, chat records, passwords and other private information belonging to famous members of the security industry. Evidently they captured the data by breaching the web servers of Kevin Mitnick, Dan Kaminsky and Julien Tinners. They boast of having captured 75,000 clear-text passwords this way, most of them from the databases of the forum systems running on the affected servers. . The crackers explained their motivation on Dan Kaminsky's site, which has now been taken off-line. Kaminsky became known beyond the hacker scene last year for revealing an error in the DNS system. The crackers criticise the famous hackers for exaggerating security problems in the media in order to promote their own careers, accusing Kaminsky of only seeking bugs that the media will publicise and saying that Mitnick, who at one time was arrested for his hacks, is only living off the fame of yesteryear. Both are sneered at as lacking in specialist knowledge, as evidenced by these attacks. The authors of ZF0 also attack the close cooperation between the White Hat hackers and the industry, and condemn their responsible disclosure of the security vulnerabilities they find. The link for this article located at H Security is no longer available. . The crackers explained their motivation on Dan Kaminsky's site, which has now been taken off-line. K. black, security, conference, crackers, published, comprehensive, document. . Anthony Pell
Update: Project founder responds below . "SmoothWall does not use shadowed passwords in their firewall implementation. While this is not inherently dangerous as firewall systems are not designed as multi-user, an unauthorized user gaining access to the system via exploitation . . . . Update: Project founder responds below . "SmoothWall does not use shadowed passwords in their firewall implementation. While this is not inherently dangerous as firewall systems are not designed as multi-user, an unauthorized user gaining access to the system via exploitation of an unprivileged process may be able to gain administrative access by copying the password hash, and launching a brute force cracking program against it." It seems several smoothwall developers have developed an attitude towards accepting criticizm from other security professionals and don't feel this is an issue that deserves their attention. The issue escalated when the lead person responsible for the project called it "Trench Warfare." It seems he doesn't take criticism too well? Is the state of the project in jeopardy? Is there a battle going on between the people developing the project and attitude towards their users? Are there other security holes that aren't being fixed? Users interested in a system not succeptible to this security vulnerability might try Slackware. Users interested in a web-managable secure solution might try EnGarde. Update 13:49 EST - Richard Morell, smoothwall project founder, responded to LinuxSecurity.com with the following email. It certainly wasn't our intention to mislead. We report, you decide. There is also a page on their site now that provides their perspective. Subject: Factual reporting of the article you posted Date: Fri, 18 Jan 2002 17:13:49 +0000 From: Richard Morrell To:
Get the latest Linux and open source security news straight to your inbox.