Feeds

Adobe Connect breach pops lid off 'Letmein' logins of gov, army types

Plus: Did someone forget the salt?

Seven Steps to Software Security

A breach of Adobe's Connectusers.com forum database has once again exposed password security foibles, as well as website security shortcomings on Adobe's part.

Adobe suspended the forum on Tuesday night in response to the hack, as previously reported. The software developer stressed in a statement that its Adobe Connect web conferencing service itself was not affected by the breach.

An Egyptian hacker named "ViruS_HimA" has stepped forward to claim he hacked into "one of Adobe's servers" before extracting a database containing email addresses, password hashes and other information of over 150,000 Adobe customers, partners and employees.

ViruS_HimA published a limited set of records for users with email addresses ending in adobe.com, .mil and .gov as a means to substantiate his claims on Pastebin.

A statement from Adobe spokeswoman Wiebke Lips appears to back up this claim. Lips said: "The forum has a total of about 150,000 registered users. The attacker leaked 644 records."

She added: "We reset the passwords of all Connectusers.com forum members and are reaching out to those members with instructions on how to set up new passwords once the forum services are restored."

In the Pastebin leak post, which has since been pulled, ViruS_HimA said he had targeted Adobe because of shortcomings in its handling of security reports. He promised a leak against Yahoo! would follow.

Analysis of the leak sample by Paul Ducklin, head of technology, Asia Pacific at Sophos, shows that Adobe used MD5, a hashing protocol known to be weak. It also failed to salt password hashes, an extra security precaution that thwarts brute force attacks based on compiling rainbow tables of password hashes from dictionaries of plain text passwords.

Ducklin reports that some of the 644 leaked password hashes corresponded to lame passwords such as "Letmein", "123456" and "welcome" all multiple entrants on the list. Passwords like breeze and connect (Adobe product names) appear four times each, he adds.

Tal Be'ery, a security researcher at Imperva, said an examination of the leak data suggested it came from a valid but old database.

"We compared some names in the leaked files against Linkedin.com and found out that the names in the file were people who had worked for Adobe but no longer employed there. This suggests that this list is valid [but] the hacked database is probably pretty old." Password hashes were not salted to guard against brute force cracking attacks, Be'ery adds.

"Based on an analysis of the leaked data, the password hashes - encrypted versions of the passwords - stored in the compromised Adobe database had been generated with MD5, a cryptographic hash function that's known to be insecure. This means that they can easily be cracked to recover the original passwords," he concludes. ®

Mobile application security vulnerability report

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
BMW's ConnectedDrive falls over, bosses blame upgrade snafu
Traffic flows up 20% as motorway middle lanes miraculously unclog
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Attackers raid SWISS BANKS with DNS and malware bombs
'Retefe' trojan uses clever spin on old attacks to grant total control of bank accounts
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.