Yahoo fixes password-pilfering bug, explains who's at risk
Security experts continue to hammer Yahoo for storing usernames and passwords in plain text
Computerworld - Yahoo today said it has fixed the flaw that allowed hackers to steal more than 450,000 passwords from one of its many services.
The company also provided more information about whose passwords had been pilfered.
"We have...now fixed this vulnerability, deployed additional security measures for affected Yahoo! users, enhanced our underlying security controls and are in the process of notifying affected users," the company announced in a post to its blog early Friday.
Yahoo has offered no specific information about the attack, how it was carried out or even when. It confirmed the attack Thursday.
The hacker group D33Ds Company took responsibility for the breach, saying it had exploited a basic SQL injection vulnerability in a Yahoo service to steal the usernames and passwords associated with 453,000 accounts. The group published the passwords and email addresses on the Web.
Yahoo also confirmed that the stolen account credentials belonged to registered users of its Yahoo Contributor Network, which was previously known as Associated Content.
Yahoo Contributor Network is a platform that generates high-volume, low-cost content by letting writers photographers, and others share their work with Yahoo members and earn money based on the traffic their content generates. Users who contribute to the network are required to sign in using a Yahoo, Google or Facebook ID.
Associated Content, which was founded in 2005, was bought by Yahoo for just over $100 million in May 2010. Yahoo renamed the service in late 2011, when it also launched Yahoo Voices, a portal where users access content posted by the Yahoo Contributor Network.
According to Yahoo, only people who registered as providers with Associated Content before the 2010 acquisition were affected by the password theft. "[The] compromised file was a standalone file that was not used to grant access to Yahoo! systems and services," Yahoo maintained.
Just under a third of the stolen passwords were linked to accounts registered to a yahoo.com email address, security company Rapid7 said Thursday. Significant chunks of the file, however, were composed of Gmail (23.6% of all accounts) and Hotmail (12.2%) addresses.
All users with older Associated Content accounts, no matter the email address used, should immediately change the passwords for those email accounts as well as any identical or similar passwords used to secure other online services or websites, security experts have said.
Rapid7 security researcher Marcus Carey said yesterday that the file published by D33Ds included 123 government email accounts -- ones ending with ".gov" -- and 235 military-related addresses (ending with ".mil"). Among the government email accounts, Carey found several associated with the FBI, the Transportation Security Administration (TSA) and the Department of Homeland Security (DHS).
Security experts have been scathing in their criticism of Yahoo, in large part because the passwords were stored in plain-text, making the hackers' job of exploiting the stolen accounts a breeze.
Yesterday, Mark Bower, a data protection expert and executive at Voltage Security, said, "It's utter negligence to store passwords in the clear."
Also on Thursday, Rob Rachwald, director of security strategy at Imperva, took Yahoo to the woodshed. "To add insult to injury, the passwords were stored in clear text and not hashed (encoded)," Rachwald wrote in a blog post. "One would think the recent LinkedIn breach would have encouraged change, but no. Rather, this episode will only inspire hackers worldwide."
The LinkedIn breach Rachwald referenced came to light last month, and involved approximately 6.5 million encrypted passwords belonging to members of the networking service.
In its Friday blog, Yahoo again apologized to users affected by the password theft.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer, on Google+ or subscribe to Gregg's RSS feed
. His email address is gkeizer@computerworld.com.
See more by Gregg Keizer on Computerworld.com.
Data breaches
- Yahoo Japan says 22 million user IDs may have been stolen
- Payment card processors hacked in $45 million fraud
- The Onion explains how its Twitter account was hacked
- Name.com forces customers to reset passwords following security breach
- Systems manager arrested for hacking former employer's network
- Dutch bill would give police hacking powers
- After hack, LivingSocial tells 50M users to reset passwords
- Amazon looks to move security appliances to the cloud
- Gh0stRAT malware attacks continue, researcher says
- AP Twitter hack looks like a security tipping point
Read more about Cybercrime and Hacking in Computerworld's Cybercrime and Hacking Topic Center.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- ESG: The Contemporary Value of Virtual Storage Appliances: HP renews its focus with StoreVirtual VSA A good virtual storage appliance (VSA) can simultaneously make good business sense and deliver operational value by allowing users to avoid the additional...
- Taneja Group: HP 3PAR StoreServ 7000 - Enterprise for the Mid-range In this report, the Taneja Group takes an objective, in-depth look at the features of the HP 3PAR StoreServ 7000 powered by Intel...
- Edison Group: Stepping Up to the Next Generation: The Business Value of Upgrading from HP EVA Storage to 3PAR StoreServ Storage HP EVA Storage users who face performance and scalability tradeoffs should consider an upgrade to 3PAR StoreServ Storage, powered by Intel Xeon processors.
- Taneja Group: Ensuring Business Continuity of SAN Storage with the HP 3PAR StoreServ 7000 Family Built from the ground up with business continuity in mind, Taneja reviews the HP 3PAR StoreServ 7000 array, powered by Intel Xeon processors,...
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in...
- Enterprise File Sharing: All You Need to Know Security. Scalability. Control. These are just some of the many benefits of enterprise cloud file-sharing that you'll discover in this KnowledgeVault, packed with... All Cybercrime and Hacking White Papers | Webcasts
