Login information for 453,000 users of Yahoo! Voice was posted to the web early today. The Hacker group D33DS Company claim credit.
The group left a text file of the information along with a message to Yahoo! on d33ds.co. That site, as of this morning was down. In the message, the hackers said, “We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat.” The group did not divulge the Yahoo! service however, they said it was to “to avoid further damage.”
It is reported that the hackers used a union-based SQL injection to get into the Yahoo! Subdomain.This type of attack uses code inside searches and other user input fields to “trick” servers to divulge large portions of data and other very sensitive information.
|
|
Yahoo! confirmed the hack of Yahoo! Voices today. They report approximately 400,000 logins were breached. Yahoo! also reported that less than five% of the passwords linked to the accounts were valid ones.
Yahoo! stated in their release, “At Yahoo! we take security very seriously and invest heavily in protective measures to ensure the security of our users and their data across all our products. We are fixing the vulnerability that led to the disclosure of this data, changing the passwords of the affected Yahoo! users and notifying the companies whose users accounts may have been compromised.”
Related Content
Eset a European Security firm, pulled the data from the now-downed site and analyzed the hacked data to show the top ten passwords used by users of Yahoo! Voice, in order of first-to-last, they were: 123456, password, welcome, ninja, abc123, 123456789, 12345678, sunshine, princess, and qwerty.
It is recommended that users of the service access their accounts and change their password information. This practice should be done on a regular basis.






