<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: bsdnews]]></title>
    <link>http://securityratty.com/tag/bsdnews</link>
    <description></description>
    <pubDate>Fri, 25 Apr 2008 04:10:33 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[BSDNews.com is hacked and user information is exposed]]></title>
      <link>http://securityratty.com/article/f933fe4ac705793824eb3c93ab71171c</link>
      <guid>http://securityratty.com/article/f933fe4ac705793824eb3c93ab71171c</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/24/08 (This report was postponed for 24 hours to allow for the site administrator to respond and notify affected people

Organization
Daemon News

At...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/BSDNews.jpg" align="right" height="76" width="200"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/24/08 (This report was postponed for 24 hours to allow for the site administrator to respond and notify affected people)<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.daemonnews.org">Daemon News</a>* <br><br><font size="1">*At the time of this writing, the Daemon News web site was not available.</font><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.bsdnews.com">BSDNews.com</a>** <br><br><font size="1">**At the time of this writing, the BSDNews.com web site was not available.</font><br><br><span style="font-weight: bold;">Victims:</span><br>BSDNews.com members<br><br><span style="font-weight: bold;">Number Affected:</span><br>5498<br><br><span style="font-weight: bold;">Types of Data:</span><br>Username, password, email address, and in some cases real names<br><br><span style="font-weight: bold;">Breach Description:</span><br>It appears that the BSDNews.com web site may have been compromised through an exploit of a file named "bottom.php3", which was used by the site.&nbsp; The attacker was able to access and download user account information.&nbsp; As of the time of this writing, BSDNews.com is offline.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.golden-warez.com/forum/viewtopic.php?p=391&amp;hilit=5498">Golden-Warez</a> <br><a href="http://indounderground.org/?p=55">Indonesia Underground Blog</a> <br><a href="http://www.elwood.net">Jim O'Gorman's Site</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>Brought to the attention of The Breach Blog by <a href="http://www.elwood.net">Jim O'Gorman</a> <br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br><img src="http://images.quickblogcast.com/95781-88451/bsdnewshack.jpg" border="0" width="600"><br><br>"Hi all, maybe some of you, saw that bsdnews.com is/was offline.<br><br>I hacked their database, with an exploit found by myself. <br>I tried to submit to milw0rm, but they dont accept exploits of .php3 .<br><br>bottom.php3 , this file was vulnerability.<br><br>LOL, ok.. But i have their user database.<br>I dont want to waste my time to check the hole thing..<br><br>first word is username, second word is password, third word is email adress. B<br>By some lines the password,email is NULL.<br><br>Do what you want to do with it..<br>Please, if u think i didnt hacked it, search forums/google , you dont find anything<br><br>THIS IS MY FIRST RELEASE HERE!<br><br>i kept everything as i got it&nbsp; so there can be info what is usefull<br><br>uploaded at my host"<i><br>[Evan] There is a link in this Golden-Warez post that leads to a compressed (.rar) file.&nbsp; In the RAR there are two text files that each contain ~1000 records.&nbsp; I don't generally suggest that people make it a habit to go to warez sites and download files.&nbsp; If you are going to anyway, then don't claim that I told you to.</i><br><br><img src="http://images.quickblogcast.com/95781-88451/bsdindonesia.jpg" border="0" width="403"><br><br><span style="font-weight: bold;">Commentary:</span><br>OK.&nbsp; Some of you may be asking the question, so what?&nbsp; The "hacker" only compromised usernames, email addresses and passwords allowing access to BSDNews.com, which doesn't store financial, health, or other personal information, right?&nbsp; Well, kind of.&nbsp; The problem is the fact that a password is itself confidential personal information.&nbsp; According to some estimates, as many as 70% of people use the same or similar password for access to multiple or all sites that they use.&nbsp; Take PayPal for instance.&nbsp; This breach compromised email addresses and passwords.&nbsp; If a person uses the same password at PayPal as they do at BSDNews.com, then a bad guy can easily access the PayPal account of the victim and wreak all kinds of havoc.&nbsp; This is the issue.&nbsp; Out of a claimed 5498 accounts, don't you think that there is a good chance that something like this will be the case with at least a few?<br><br>A couple of suggestions.&nbsp; If you are one of the people that uses a single (or similar) password to access multiple online accounts, change this habit.&nbsp; Use a different password for each account, especially the accounts that are sensitive like online banking, PayPal, etc.&nbsp; If managing all of these passwords becomes a pain in the rear, then use a password management program such as <a href="http://passwordsafe.sourceforge.net/">Password Safe</a> (Thank You Bruce Schneier) or <a href="http://www.roboform.com/">RoboForm</a>.&nbsp; If you happen to be one of the many victims of this breach, change your passwords now and be aware.<br><br>Jim O'Gorman sent multiple emails to the site administrator(s) at BSDNews.com urging them to do the right thing and notify all affected persons.&nbsp; It appears that this has not happened yet.&nbsp; Jim shared the multiple emails back and forth between him and the site administrator(s).&nbsp; We still have not seen an actual notification.&nbsp; A special thanks to Jim for his awareness and diligent work to get a resolution! <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/25/bsdnews.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 25 Apr 2008 04:10:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bsdnews">bsdnews</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <category domain="http://securityratty.com/tag/password management program">password management program</category>
      <category domain="http://securityratty.com/tag/site administrator">site administrator</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/password safe">password safe</category>
      <category domain="http://securityratty.com/tag/similar password">similar password</category>
      <category domain="http://securityratty.com/tag/similar">similar</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <source url="http://breachblog.com/2008/04/25/bsdnews.aspx">BSDNews.com is hacked and user information is exposed</source>
    </item>
  </channel>
</rss>
