Hackers expose phone information of 4.6M Snapchat users
A security firm had pointed to a vulnerability that could help attackers find the phone numbers of many users
IDG News Service - Phone numbers paired with user names of over 4.6 million alleged Snapchat users were posted online by hackers, a few days after a security research group claimed a vulnerability in the social sharing service that could allow attackers to match phone numbers to Snapchat accounts.
"This database contains username and phone number pairs of a vast majority of the Snapchat users," said a post on website SnapchatDB.info. The account has since been suspended, apparently by the hosting service. A cached version of the site can be viewed here.
The information was acquired through the recently patched Snapchat exploit and is being shared with the public to raise awareness on the issue, according to the post. "The company was too reluctant at patching the exploit until they knew it was too late and companies that we trust with our information should be more careful when dealing with it," it added.
The hackers said they had "censored" for now the last two digits of the phone numbers in order to minimize spam and abuse, but asked people to contact them for the uncensored database, which they may agree to release under certain circumstances.
Gibson Security had published proof-of-concept code last week that takes advantage of the "find_friends" feature in the Snapchat application programming interface (API) to iterate and match the phone numbers of users to their Snapchat accounts in a short period of time. Gibson first revealed the vulnerability and other issues in August.
"Theoretically, if someone were able to upload a huge set of phone numbers, like every number in an area code, or every possible number in the U.S., they could create a database of the results and match usernames to phone numbers that way," Snapchat wrote in response last week. "Over the past year we've implemented various safeguards to make it more difficult to do," it added. "We recently added additional counter-measures and continue to make improvements to combat spam and abuse."
After the release of the SnapchatDB database, Gibson said in a Twitter message that it knew nothing about SnapchatDB, but it was a matter of time until something like it happened. "Also the exploit works still with minor fixes," it added.
Snapchat could not be immediately reached for comment.
"People tend to use the same username around the web so you can use this information to find phone number information associated with Facebook and Twitter accounts, or simply to figure out the phone numbers of people you wish to get in touch with," according to the post on SnapchatDB.info.
- Path Selection Infographic Path Selection Infographic
- Hyperconvergence Infographic A wide range of observers agree that data centers are now entering an era of "hyperconvergence" that will raise network traffic levels faster...
- Preparing Your Infrastructure for the Hyperconvergence Era From cloud computing and virtualization to mobility and unified communications, an array of innovative technologies is transforming today's data centers.
- How WAN Optimization Helps Enterprises Reduce Costs If you wanted to break down innovation into a tidy equation, it might go something like this: Technology + Connectivity = Productivity. Productivity...
- Data Protection and Disaster Recovery with iSCSI and VMware Get this on demand webcast now
- Cloud Knowledge Vault Learn how your organization can benefit from the scalability, flexibility, and performance that the cloud offers through the short videos and other resources... All Privacy White Papers | Webcasts
Our new weekly Consumerization of IT newsletter covers a wide range of trends including BYOD, smartphones, tablets, MDM, cloud, social and what it all means for IT. Subscribe now and stay up to date!