miércoles, 23 de diciembre de 2009

Rockyou.com Sufre Ataque Inject SQL Comprometiendo Información Personal De Clientes



A través de un complemento Myspace el sitiorockyou.com ha sidovictima de un ataque sql injection exponiendo mas de 32 milliones de contraseñas en un archivo de texto plano. Podemos ver algunos:


Data ReleaseUser [52]
================
1|Ryo|eng-ryo|roc***|ryo@rockyou.com|1
2|Jia|eng-jia|DuF***|jia@rockyou.com|1
3|Kazu|dev-kazu|nlj***|kazu@rockyou.com|0
4|Lance|eng-lance|frU***|lance@rockyou.com|1
5|Raymond|eng-raymond|h45***|raymond@rockyou.com|1
6|James|eng-james|te9***|james@rockyou.com|1
7|Ernest|ads-ernest|7RQ***|ernest@rockyou.com|1
8|Dathan|eng-dathan|yoy***|dathan@rockyou.com|1
9|David Ma|art-david|4Pa***|david@rockyou.com|0
10|Vinay|pm-vinay|xa3***|vinay@rockyou.com|0
11|Jennifer|pm-jen|KA9***|jennifer@rockyou.com|0
12|Kenneth|dev-kenneth|Xa8***|kenneth@rockyou.com|0
13|Jeremy Tan|dev-jeremyt|HLH***|jeremyt@rockyou.com|0
14|John Hwang|pm-johnh|raG***|johnh@rockyou.com|0
15|Tim|pm-tim|gen***e|tim@rockyou.com|0
16|Arthur Chen|pm-arthur|art***c|authurc@rockyou.com|0
17|Eric|pm-eric|67E***|eric@rockyou.com|0
18|Andrew|pm-andrew|SQN***|andrew@rockyou.com|0
22|John Gentilin|ads-john|sp8***|john@rockyou.com|0
21|Shamik|ads-shamik| Es***|shamik@rockyou.com|0
26|Chuck|eng-chuck|bRe***|chuck@rockyou.com|0
19|Sandy|pm-sandy|stE***|sandy@rockyou.com|0
23|Alex Grichuk|eng-alexander|5uw***|alexander@rockyou.com|1
24|Ibrahim|eng-ibrahim|AF$***|ibrahim@rockyou.com|1
25|Len|eng-len|&Ab***|len@rockyou.com|1

Data Partner [139]
================
1|ryonations|aho*****|ryo ishizuka
9|mekatek@gmail.com|460*****|jia
12|albert_magnuson@yahoo.com|num*****|Friendster
13|ro@rockyou.com|460*****|altamerc
14|admin@bstar.com|461*****|bStar
18|ododo@dodood.com|461*****|dddee
19|rsiu@tickleinc.com|jka*****|ringo
20|ajmagnu@gmail.com|461*****|AJ's Site
21|jia@rockyou.com|mek*****|rockstar
22|peter@rockyou.com|461*****|peter
23|eugene.j.park@gmail.com|461*****|eugenejpark
24|eugene@flixster.com|pas*****|Flixster
25|nemwmin@aol.com|462*****|Adam
26|aj@rockyou.com|xan*****|Xanga
27|greg@asw.com|464*****|asw
28|gareth@asw.com|464*****|asmallworld
29|grendler@socialconcepts.com|fre*****|fubar
30|kenny@amikoo.com|464*****|Amikoo
31|support@piczotube.co.uk|465*****|PiczoTube
32|joelovesfishing246@hotmail.com|465*****|Media Dump
33|adam@urtab.com|suz*****|UrTab
34|bodenpat@iclltd.com|bad*****|Badongo
35|business@zorpia.com|465*****|Zorpia
36|lycan@groovenet.ph|465*****|GrooveNet
37|w.steward@fileden.com|466*****|FileDen

Data UserAccount [32603388]
================
1|jennaplanerunner@hotmail.com|mek*****|myspace|0|bebo.com
2|phdlance@gmail.com|mek*****|myspace|1|
3|jennaplanerunner@gmail.com|mek*****|myspace|0|
5|teamsmackage@gmail.com|pro*****|myspace|1|
6|ayul@email.com|kha*****|myspace|1|tagged.com
7|guera_n_negro@yahoo.com|emi*****|myspace|0|
8|beyootifulgirl@aol.com|hol*****|myspace|1|
9|keh2oo8@yahoo.com|cai*****|myspace|1|
10|mawabiru@yahoo.com|pur*****|myspace|1|
11|jodygold@gmail.com|att*****|myspace|1|
12|aryan_dedboy@yahoo.com|iri*****|myspace|0|
13|moe_joe_25@yahoo.com|725*****|myspace|1|
14|xxxnothingbutme@aol.com|1th*****|myspace|0|
15|meandcj069@yahoo.com|too*****|myspace|0|
16|stacey_chim@hotmail.com|cxn*****|myspace|1|
17|barne1en@cmich.edu|ilo*****|myspace|1|
18|reo154@hotmail.com|ecu*****|myspace|1|
19|natapappaslie@yahoo.com|tor*****|myspace|0|
20|ypiogirl@aol.com|tob*****|myspace|1|
21|brittanyleigh864@hotmail.com|bet*****|myspace|1|myspace.com
22|topenga68@aol.com|che*****|myspace|0|
23|marie603412@yahoo.com|cat*****|myspace|0|
24|mellowchick41@aol.com|chu*****|myspace|0|
25|baiko0o@aol.com|may*****|myspace|0|
26|indahamzah84@hotpop.com|lov*****|myspace|0|


Fuentes:
http://www.net-security.org/secworld.php?id=8612
http://igigi.baywords.com/rockyou-com-exp
http://www.whatsmypass.com/rockyou-got-rocked

No hay comentarios:

Publicar un comentario