Resultaten 1 tot 15 van de 28
Pagina 1 van de 2 1 2 LaatsteLaatste
Geen

Onderwerp: Linkedin gehacked

  1. #1
    Linkedin gehacked
    geregistreerd gebruiker
    48 Berichten
    Ingeschreven
    02/06/06

    Locatie
    Eindhoven

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked


    Registrar SIDN: nee
    KvK nummer: nvt
    Ondernemingsnummer: nvt

    Thread Starter

    Linkedin gehacked

    Het is zojuist bekend geworden dat Linkedin gehacked is, het zou gaan om een bestand met 6,5 miljoen sha-1 encrypted wachtwoorden. Usernames staan niet in de dump file maar verwacht word dat deze ook buit gemaakt zijn.

    Dit is op zich wel zorgelijke informatie who's next ? Facebook ? Gmail ?

  2. #2
    Linkedin gehacked
    Programmeur / Hoster
    3.952 Berichten
    Ingeschreven
    20/06/06

    Locatie
    Wijlre

    Post Thanks / Like
    Mentioned
    28 Post(s)
    Tagged
    0 Thread(s)
    647 Berichten zijn liked


    Naam: John Timmer
    Bedrijf: SystemDeveloper.NL
    Functie: Eigenaar
    URL: www.systemdeveloper.nl
    KvK nummer: 14083066
    View johntimmer's profile on LinkedIn

    sha-1 is geen encryptie

  3. #3
    Linkedin gehacked
    geregistreerd gebruiker
    48 Berichten
    Ingeschreven
    02/06/06

    Locatie
    Eindhoven

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked


    Registrar SIDN: nee
    KvK nummer: nvt
    Ondernemingsnummer: nvt

    Thread Starter
    Citaat Oorspronkelijk geplaatst door systemdeveloper Bekijk Berichten
    sha-1 is geen encryptie
    Hash maar ze waren ook niet salted dus eenvoudig te kraken. Mijn hash stond er tussen dus inmiddels mijn wachtwoord veranderd.

  4. #4
    Linkedin gehacked
    administrator
    21.459 Berichten
    Ingeschreven
    17/12/01

    Locatie
    Amsterdam

    Post Thanks / Like
    Mentioned
    71 Post(s)
    Tagged
    0 Thread(s)
    590 Berichten zijn liked


    Naam: Domenico Consoli
    Bedrijf: Webhostingtalk.nl
    Functie: Oprichter
    URL: webhostingtalk.nl
    Registrar SIDN: Ja
    KvK nummer: 51327317
    TrustCloud: domenico
    View domenicoconsoli's profile on LinkedIn

    Wachtwoord ook al veranderd ja. Ik ben benieuwd hoe ze dit voor elkaar hebben gekregen.

  5. #5
    Linkedin gehacked
    moderator
    6.052 Berichten
    Ingeschreven
    21/05/03

    Locatie
    NPT - BELGIUM

    Post Thanks / Like
    Mentioned
    40 Post(s)
    Tagged
    0 Thread(s)
    481 Berichten zijn liked


    Naam: Dennis de Houx
    Bedrijf: All In One
    Functie: Zaakvoerder
    URL: www.all-in-one.be
    Ondernemingsnummer: 0867670047

    Citaat Oorspronkelijk geplaatst door Jantjedeman Bekijk Berichten
    Hash maar ze waren ook niet salted dus eenvoudig te kraken. Mijn hash stond er tussen dus inmiddels mijn wachtwoord veranderd.
    Tja dat zo een bedrijven nog niet doorhebben dat je dingen moet "salten" kan er bij niet in. Het is de dag van vandaag veel te simpel geworden met wat gpu's en deftige rainbowtables om hashes te decrypten in een mum van tijd.
    Dennis de Houx - All In One ~ Official ISPsystem partner

    Lees hier de webhostingtalk.nl forum regels en voorwaarden!

  6. #6
    Linkedin gehacked
    administrator
    21.459 Berichten
    Ingeschreven
    17/12/01

    Locatie
    Amsterdam

    Post Thanks / Like
    Mentioned
    71 Post(s)
    Tagged
    0 Thread(s)
    590 Berichten zijn liked


    Naam: Domenico Consoli
    Bedrijf: Webhostingtalk.nl
    Functie: Oprichter
    URL: webhostingtalk.nl
    Registrar SIDN: Ja
    KvK nummer: 51327317
    TrustCloud: domenico
    View domenicoconsoli's profile on LinkedIn

    Good. Your password hash is not amongst the 6458020 leaked hashes!

  7. #7
    Linkedin gehacked
    Professional
    3.115 Berichten
    Ingeschreven
    05/02/05

    Locatie
    Alkmaar

    Post Thanks / Like
    Mentioned
    7 Post(s)
    Tagged
    0 Thread(s)
    101 Berichten zijn liked


    Naam: Thomas
    Registrar SIDN: JA
    ISPConnect: Lid
    KvK nummer: 76706966

    Het interessante is dat iedereen nu hun wachtwoord aan het wijzigen is maar nergens nog bekend is of er echt een lek is en als deze er al is of het is opgelost. Misschien wijzigt iedereen zijn wachtwoord nu en ligt ook dat wachtwoord op straat.

  8. #8
    Linkedin gehacked
    administrator
    21.459 Berichten
    Ingeschreven
    17/12/01

    Locatie
    Amsterdam

    Post Thanks / Like
    Mentioned
    71 Post(s)
    Tagged
    0 Thread(s)
    590 Berichten zijn liked


    Naam: Domenico Consoli
    Bedrijf: Webhostingtalk.nl
    Functie: Oprichter
    URL: webhostingtalk.nl
    Registrar SIDN: Ja
    KvK nummer: 51327317
    TrustCloud: domenico
    View domenicoconsoli's profile on LinkedIn

    Update, 17:03: Het lijkt te gaan om een verouderde database met wachtwoorden.

    https://twitter.com/#!/LinkedInNews
    Our team continues to investigate, but at this time, we're still unable to confirm that any security breach has occurred. Stay tuned here.
    Some observations on this file:
    0. This is a file of SHA1 hashes of short strings (i.e. passwords).

    1. There are 3,521,180 hashes that begin with 00000. I believe that these represent hashes that the hackers have already broken and they have marked them with 00000 to indicate that fact.

    Evidence for this is that the SHA1 hash of 'password' does not appear in the list, but the same hash with the first five characters set to 0 is.


    5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8 is not present
    000001e4c9b93f3f0682250b6cf8331b7ee68fd8 is present

    Same story for 'secret':

    e5e9fa1ba31ecd1ae84f75caaa474f3a663f05f4 is not present
    00000a1ba31ecd1ae84f75caaa474f3a663f05f4 is present

    And for 'linkedin':

    7728240c80b6bfd450849405e8500d6d207783b6 is not present
    0000040c80b6bfd450849405e8500d6d207783b6 is present

    2. There are 2,936,840 hashes that do not start with 00000 that can be attacked with JtR.
    3. The implication of #1 is that if checking for your password and you have a simple password then you need to check for the truncated hash.

    4. This may well actually be from LinkedIn. Using the partial hashes (above) I find the hashes for passwords linkedin, LinkedIn, L1nked1n, l1nked1n, L1nk3d1n, l1nk3d1n, linkedinsecret, linkedinpassword, ...

    5. The file does not contain duplicates. LinkedIn claims a user base of 161m. This file contains 6.4m unique password hashes. That's 25 users per hash. Given the large amount of password reuse and poor password choices it is not improbable that this is the complete password file. Evidence against that thesis is that password of one person that I've asked is not in the list.
    Laatst gewijzigd door Domenico; 06/06/12 om 17:40.

  9. #9
    Linkedin gehacked
    geregistreerd gebruiker
    48 Berichten
    Ingeschreven
    02/06/06

    Locatie
    Eindhoven

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked


    Registrar SIDN: nee
    KvK nummer: nvt
    Ondernemingsnummer: nvt

    Thread Starter
    Update nog vergeten te vermelden hash file is te vinden op:

    https://disk.yandex.net/disk/public/...uGtgOEptAS4%3D

  10. #10
    Linkedin gehacked
    geregistreerd gebruiker
    48 Berichten
    Ingeschreven
    02/06/06

    Locatie
    Eindhoven

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked


    Registrar SIDN: nee
    KvK nummer: nvt
    Ondernemingsnummer: nvt

    Thread Starter
    Citaat Oorspronkelijk geplaatst door getUP Bekijk Berichten
    Het interessante is dat iedereen nu hun wachtwoord aan het wijzigen is maar nergens nog bekend is of er echt een lek is en als deze er al is of het is opgelost. Misschien wijzigt iedereen zijn wachtwoord nu en ligt ook dat wachtwoord op straat.
    Het is geen 1 april he , nee de dump komt van een gerenomeerd hackers forum af het is dus zeer onwaarschijnlijk dat dit een grap of iets anders is. Tevens raad Linkedin nu ook aan om je wachtwoord te veranderen.

  11. #11
    Linkedin gehacked
    Professional
    3.115 Berichten
    Ingeschreven
    05/02/05

    Locatie
    Alkmaar

    Post Thanks / Like
    Mentioned
    7 Post(s)
    Tagged
    0 Thread(s)
    101 Berichten zijn liked


    Naam: Thomas
    Registrar SIDN: JA
    ISPConnect: Lid
    KvK nummer: 76706966

    Dat was niet het punt wat ik wilde maken. Mensen wijzigen direct hun wachtwoord maar weten niet of een lek is opgelost. Dat lijkt mij nogal onverstandig.

  12. #12
    Linkedin gehacked
    geregistreerd gebruiker
    1.265 Berichten
    Ingeschreven
    18/01/06

    Locatie
    Almere

    Post Thanks / Like
    Mentioned
    3 Post(s)
    Tagged
    0 Thread(s)
    30 Berichten zijn liked


    Naam: Rens
    URL: www.yisp.nl
    KvK nummer: 08144415

    Zowel die van mij als van m'n vriendin staan er niet in, dus is zeker geen complete file.
    Yisp.nl - High bandwidth solutions in YISP-AS(58073) - www.yisp.nl

  13. #13
    Linkedin gehacked
    administrator
    21.459 Berichten
    Ingeschreven
    17/12/01

    Locatie
    Amsterdam

    Post Thanks / Like
    Mentioned
    71 Post(s)
    Tagged
    0 Thread(s)
    590 Berichten zijn liked


    Naam: Domenico Consoli
    Bedrijf: Webhostingtalk.nl
    Functie: Oprichter
    URL: webhostingtalk.nl
    Registrar SIDN: Ja
    KvK nummer: 51327317
    TrustCloud: domenico
    View domenicoconsoli's profile on LinkedIn

    Update 22:00 LinkedIn heeft de hack bevestigd.

    An Update on LinkedIn Member Passwords Compromised

    Vicente Silveira, June 6, 2012

    We want to provide you with an update on this morning’s reports of stolen passwords. We can confirm that some of the passwords that were compromised correspond to LinkedIn accounts. We are continuing to investigate this situation and here is what we are pursuing as far as next steps for the compromised accounts:

    1. Members that have accounts associated with the compromised passwords will notice that their LinkedIn account password is no longer valid.
    2. These members will also receive an email from LinkedIn with instructions on how to reset their passwords. There will not be any links in these emails. For security reasons, you should never change your password on any website by following a link in an email.
    3. These affected members will receive a second email from our Customer Support team providing a bit more context on this situation and why they are being asked to change their passwords.

    It is worth noting that the affected members who update their passwords and members whose passwords have not been compromised benefit from the enhanced security we just recently put in place, which includes hashing and salting of our current password databases.

    We sincerely apologize for the inconvenience this has caused our members. We take the security of our members very seriously. If you haven’t read it already it is worth checking out my earlier blog post today about updating your password and other account security best practices.
    Let je ook op dat wat ik in BOLD heb gezet?
    Laatst gewijzigd door Domenico; 06/06/12 om 22:47.

  14. #14
    Linkedin gehacked
    geregistreerd gebruiker
    48 Berichten
    Ingeschreven
    02/06/06

    Locatie
    Eindhoven

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked


    Registrar SIDN: nee
    KvK nummer: nvt
    Ondernemingsnummer: nvt

    Thread Starter
    Citaat Oorspronkelijk geplaatst door Domenico Bekijk Berichten
    Update 22:00 LinkedIn heeft de hack bevestigd.


    Let je ook op dat wat ik in BOLD heb gezet?
    Hahha ja en sha-1 unsalted gebruiken

    @GetUP, je kan nooit zeker genoeg zijn, wijzigen en later nogmaals just to be sure. Maar snap je punt. Ik heb wel het vermoeden dat Linkedin al op de hoogte was aangezien de hack 2 dagen geleden al bekend was op zowel het forum alsmede bij diverse security providers.
    Laatst gewijzigd door Jantjedeman; 06/06/12 om 23:00.

  15. #15
    Linkedin gehacked
    Programmeur / Hoster
    3.952 Berichten
    Ingeschreven
    20/06/06

    Locatie
    Wijlre

    Post Thanks / Like
    Mentioned
    28 Post(s)
    Tagged
    0 Thread(s)
    647 Berichten zijn liked


    Naam: John Timmer
    Bedrijf: SystemDeveloper.NL
    Functie: Eigenaar
    URL: www.systemdeveloper.nl
    KvK nummer: 14083066
    View johntimmer's profile on LinkedIn

    Het is toch wel erg gemakzuchtig om voor belangrijke dingen md5, sha-1 eventueel zelfs met salt te gebruiken.

    Het echt encrypten is toch iets dat amper een paar regels code kost...

Pagina 1 van de 2 1 2 LaatsteLaatste

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics