Page 2 of 2 FirstFirst
1
2
  1. #21

  2. #22
    Would love a list of websites affected

  3. #23
    The Lightbringer inboundpaper's Avatar
    10+ Year Old Account
    Join Date
    Apr 2010
    Location
    Close to San Fransisco, CA
    Posts
    3,102
    Comrades, great news! Turnip harvest is going to be good. Much vodka to celebrate.
    Quote Originally Posted by Asmodias View Post
    Sadly, with those actors... the "XXX Adaptation" should really be called 50 shades of watch a different porno.
    Muh main
    Destiny

  4. #24
    Deleted
    Quote Originally Posted by smackyslap View Post
    Would love a list of websites affected
    You'd love a list with over 400 thousand lines?

  5. #25
    I am Murloc! Kuja's Avatar
    15+ Year Old Account
    Join Date
    Nov 2007
    Location
    City of Judgement
    Posts
    5,493
    Quote Originally Posted by Sydänyö View Post
    You'd love a list with over 400 thousand lines?
    Would love a list of popular websites affected. Ebay? Paypal? Mmo champ?

    My gold making blog
    Your journey towards the gold cap!


  6. #26
    I am Murloc!
    10+ Year Old Account
    Join Date
    Apr 2011
    Location
    Aarhus, Denmark, Europe
    Posts
    5,079
    Quote Originally Posted by Tradewind View Post
    the ars technica article probably has as much info as is going to be detailed this far in. As for what was affected, it's most likely just websites. SQLI is just appending SQL commands to an input or querystring that gets interpreted by the script on the website. So if you have a crappy search form that gets shot into a SQL query without any kind of escaping or cleansing (ie. "SELECT * FROM `blahblah` WHERE whatever='&$_POST['searchinput']&';") It's incredibly easy for someone to just type into that search form "blah';DROP TABLE `blahblah`;" and it would execute the entire input, deleting the table 'blahblah' in the process.

    It just boils down to poor protection measures and poor scripting. It's such an easy thing to avoid really, PHP has functions built in to cleanse and escape variables and the lot (mysqli_real_escape_string() or addslashes()) and using prepared statements (ie. bind_param()) and such for entries/updates does it all for you too.
    Reminds me of a comic..


  7. #27
    Quote Originally Posted by Sydänyö View Post
    You'd love a list with over 400 thousand lines?
    ctrl+f is pretty good man

  8. #28
    Deleted
    Quote Originally Posted by Tradewind View Post
    the ars technica article probably has as much info as is going to be detailed this far in.
    Yeah I suspected it would boil down to not having prepared statements - it's funny too since you can just grab yourself SQLmap and use that to automate scanning your website but I guess if people still use sql instead of sqli and don't sanitize, it's not going to make much of a difference.

  9. #29
    Merely a Setback Trassk's Avatar
    10+ Year Old Account
    Join Date
    Sep 2011
    Location
    Having a beer with dad'hardt
    Posts
    26,315
    I change my password with every website I use anyway.
    #boycottchina

  10. #30
    The Lightbringer Conspicuous Cultist's Avatar
    10+ Year Old Account
    Join Date
    May 2013
    Location
    Texasland
    Posts
    3,735
    Fine Погода we're having today, yes?

    Ugh... I катастрофически нужна водку.

  11. #31
    Deleted
    they probably confused the database with their alien language, just like in WoW

  12. #32
    Scarab Lord Triggered Fridgekin's Avatar
    10+ Year Old Account
    Join Date
    Jul 2011
    Location
    Nova Scotia, Canada
    Posts
    4,951
    Oh those Russians!
    A soldier will fight long and hard for a bit of colored ribbon.

  13. #33
    Deleted
    Quote Originally Posted by NuLogic View Post
    Oh no not my email accounts that I rarely use.
    err you use your email for virtually everything online

  14. #34
    Quote Originally Posted by adam86shadow View Post
    err you use your email for virtually everything online
    No, I use Steve's email for virtually everything online. He's gon' be pissed.

  15. #35
    Scarab Lord Mister Cheese's Avatar
    10+ Year Old Account
    Join Date
    Sep 2012
    Location
    New Jersey
    Posts
    4,620
    Oh no. A billion passwords. It totally will take 5 seconds to go through all of them and steal everyone's information.

    Really though it's like your PW was never stolen at all anyways. Your chances of them using this information to steal from you is incredibly low.

  16. #36
    The Lightbringer Hottage's Avatar
    15+ Year Old Account
    Join Date
    Feb 2009
    Location
    The Hague, NL
    Posts
    3,836
    I'm more disgusted that there are over a billion passwords either stored in plain text or in a format that allows for easy unobfusion.

    Then again, if you're too lazy to properly escape your SQL statements, I guess you're also too lazy to bother salting/peppering the passwords before hashing them... or even hashing them in the first place.

    My security analyst sense is convulsing.
    Dragonflight: Grand Marshal Hottage
    PC Specs: Ryzen 7 7800X3D | ASUS ROG STRIX B650E-I | 32GB 6000Mhz DDR5 | NZXT Kraken 120
    Inno3D RTX 4080 iChill | Samsung 970 EVO Plus 2TB | NZXT H200 | Corsair SF750 | Windows 11 Pro
    Razer Basilisk Ultimate | Razer Blackwidow V3 | ViewSonic XG2730 | Steam Deck 1TB OLED

  17. #37
    Epic! Wayne25uk's Avatar
    10+ Year Old Account
    Join Date
    Feb 2012
    Location
    Maltby,Rotherham
    Posts
    1,738
    First Ukraine now my bank account details,oh noes!!!!! Those dam dirty russians!!

  18. #38
    The Lightbringer
    10+ Year Old Account
    Join Date
    Mar 2014
    Posts
    3,084
    Fear not filthy capitalists. I'm sure our comrades in Beautiful Mother Russia did not do this thing. There is no problem friend. No passvords stolens. Go back to sleeps.

  19. #39
    Partying in Valhalla
    Annoying's Avatar
    15+ Year Old Account
    Join Date
    Aug 2008
    Location
    Socorro, NM, USA
    Posts
    10,657
    I'm getting a ton of password reset requests from... rift. Which I've never played.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •