Wednesday, 18 July 2012

Yahoo service SQL injection vuln leads to account exposure

The uptake given by SANSFIRE, a SQL injection vulnerability was leveraged to gain access to the Yahoo Voice service which was utilized by attackers to acquire then post login credentials for more than 453,000 user accounts that they said they retrieved in plaintext.

Password analysis of the account list proved what we've all come to expect. "The top five passwords in the stolen batch were "123456," "password," "welcome," "ninja" and "abc123," said David Harley, senior research fellow at security firm ESET."
Ninja = great skill set, bad password. :-)


 Related stories:
http://arstechnica.com/security/2012/07/yahoo-service-hacked/
http://www.mercurynews.com/business/ci_21059190/yahoo-investigating-reported-mass-password-breach