AusGamers Forums
Show: per page
1
Gawker hack
natslovR
Sydney, New South Wales
7037 posts
There's a damning writeup in Forbes today about the month long hack of Gawker. I haven't seen it mentioned here but thought it was worthwhile. Looks like they were thorougly owned with all user accounts dumped on the net, all their source code and passwords for external sites.

If you ever had an account on any of their network and password share your sites, you should change your passwords.

Edit: fixed typo. There needs to be an easier way to create new threads from mobiles :-) one that translates what I'm thinking to text.
08:35am 14/12/10 Permalink
adBot
ads
Internet
--
ads keep websites free
08:35am 14/12/10 Permalink
Spook
Brisbane, Queensland
30838 posts
subject typo, very interesting read;

seems like gawker need to make a few changes around how they operate

morale of story: dont piss on 4chan

last edited by Spook at 09:03:15 14/Dec/10
08:49am 14/12/10 Permalink
Plasma
1227 posts
A site has a page you can enter your email to check if it was in the db dump, http://www.slate.com/id/2277768/
09:08am 14/12/10 Permalink
ravn0s
Brisbane, Queensland
11717 posts
not sure if i have any accounts with gawker

edit: that sites says my email isnt in the db. guess im good

last edited by ravn0s at 09:18:57 14/Dec/10
09:16am 14/12/10 Permalink
natslovR
Sydney, New South Wales
7038 posts
Thanks for the slate link, looks like I'm safe.
09:17am 14/12/10 Permalink
d0mino
Brisbane, Queensland
5009 posts
i got got :(
09:18am 14/12/10 Permalink
Opec
Brisbane, Queensland
6947 posts
Just checked my account and I'm safe. I can't believe they don't encrypt or hashed their users' password field in the DB.....
09:32am 14/12/10 Permalink
euphoria
Gold Coast, Queensland
1867 posts
me safe. hard luck domino.

from reading that article opec, it looks like they stored them encrypted with DES encryption (not triple DES), which no one in their right mind should do as it was cracked over a decade ago.
09:40am 14/12/10 Permalink
BillyHardball
Brisbane, Queensland
11439 posts
What the hell is gawker?
09:56am 14/12/10 Permalink
Midda
Brisbane, Queensland
5870 posts
Just checked my account and I'm safe. I can't believe they don't encrypt or hashed their users' password field in the DB.....

They are encrypted.

What the hell is gawker?

A media group that owns Kotaku, Gizmodo, Lifehacker, and a few others.

That thing says my account was among those leaked, but I never created an account, I always just used the login-free posting which just required your email address. I tried logging in anyway, but none of the username/password combos I used worked, which would suggest I never actually had an account.

Doesn't really matter though, I changed all of my important passwords about a month ago anyway.
10:08am 14/12/10 Permalink
trog
AGN Admin
Brisbane, Queensland
32543 posts
What the hell is gawker?
they are the tabloid journalism of the tech world.

Still, sad news for them that they got hacked. Constant reminder that vigilance is always required. I hope they publish some info about the attack vector, if they can find it.
10:33am 14/12/10 Permalink
thermite
Brisbane, Queensland
6953 posts
I've never even heard of gawker
11:22am 14/12/10 Permalink
Pinky
Melbourne, Victoria
8049 posts
We're talking about a site that didn't even hash passwords :-/ They deserve everything they get because that's just plain lazy.
11:27am 14/12/10 Permalink
Midda
Brisbane, Queensland
5872 posts
I've never even heard of gawker

But you've heard of Kotaku, right?
11:34am 14/12/10 Permalink
thermite
Brisbane, Queensland
6954 posts
Yeah on Triple J some wannabe Steve Farrelly from kotaku commented on the r18+ thing.
12:08pm 14/12/10 Permalink
DeSavage
Sydney, New South Wales
2 posts
I (was) an advert reader of Kotaku and io9 (both owned by gawker media) and am really annoyed my main email address was leaked =(

edit: along with my decrypted password.


That thing says my account was among those leaked, but I never created an account, I always just used the login-free posting which just required your email address.


They probably stored your email address. Prepare for incoming spam...
12:32pm 14/12/10 Permalink
Trauma
Melbourne, Victoria
1062 posts
A media group that owns Kotaku, Gizmodo, Lifehacker, and a few others.

That thing says my account was among those leaked, but I never created an account, I always just used the login-free posting which just required your email address. I tried logging in anyway, but none of the username/password combos I used worked, which would suggest I never actually had an account.

Doesn't really matter though, I changed all of my important passwords about a month ago anyway.

"Correction, Dec. 13, 2010: The widget originally overstated your chances of having been compromised. If you left a comment but did not sign up for an account with Gawker, your data would not have been compromised."

Said my e-mail was not in the released data base, but no doubt is now in some other database.
05:32pm 14/12/10 Permalink
ravn0s
Brisbane, Queensland
11723 posts
apparently au versions of the sites were not compromised.
07:10pm 14/12/10 Permalink
Whoop
Brisbane, Queensland
17562 posts
I've never heard of gawker before either, heard about kotaku but don't have an account on either. Do they own any other sites? I've got multiple emails for different sites so I dunno which one(s) I should bother entering. I cbf checking all 7 or 8 of them.
08:27pm 14/12/10 Permalink
Pinky
Melbourne, Victoria
8063 posts
There was a good post on iHackerNews about storing passwords this morning:
08:22am 15/12/10 Permalink
3dee
Brisbane, Queensland
6047 posts
09:39am 15/12/10 Permalink
Spook
Brisbane, Queensland
30851 posts
yar. that was a good read too 3dee.

i would like to subscribe to jeffs newsletter
09:48am 15/12/10 Permalink
3dee
Brisbane, Queensland
6048 posts
Homer to Bart: "Your ideas are intriguing and I wish to subscribe to your newsletter."
10:13am 15/12/10 Permalink
adBot
ads
Internet
--
ads keep websites free
10:13am 15/12/10 Permalink
AusGamers Forums
Show: per page
1
This thread is archived and cannot be replied to.
 

Advertise with Us | Download Media Kit | Privacy Policy | Contact Us
© Copyright 2001-2013 AusGamers™ Pty Ltd. ACN 093 772 242.
A Mammoth Media web development, hosted by Mammoth VPS.