Feeds

Syrian Electronic Army slurps a MILLION reader passwords from Forbes

And slaps the MD5-hashed secrets all over the web

Remote control for virtualized desktops

Forbes.com has become the latest media outlet to fall to an attack by the Syrian Electronic Army (SEA) with the account records of more than a million people swiped.

A database containing email address and password combinations for 1,071,963 accounts was dumped online by the hacktivisits – including the records for Forbes contributors.

Although the passwords were one-way encrypted, the publisher strongly urged its readers to change their login secrets. The team added:

The email address for anyone registered with Forbes.com has been exposed. Please be wary of emails that purport to come from Forbes, as the list of email addresses may be used in phishing attacks. We have notified law enforcement. We take this matter very seriously and apologize to the members of our community for this breach.

Just how exactly did Forbes protect its punters' passwords? After looking through the data, Sophos reckoned the site stored the information in the PHPass Portable format: each password and a random 6-byte salt were together run through the MD5 algorithm to generate a hash, and 8,192 iterations of MD5 were performed on the hash and the password. The final result was saved to the database.

Users with particularly trivial passwords will be vulnerable to a dictionary attack; although the use of salt will slow down a miscreant, MD5 is hopelessly weak. The attackers can, say, combine the password “123456” with a particular user's salt and quickly generate a hash to check against that user's database entry. If it matches, the password is revealed; if not, try again with another similarly crap password.

Now that the data is out there, people who used their Forbes.com email address and password combination to log into various other websites are at risk of losing control of multiple web accounts.

"It took about an hour, using one core of a vanilla laptop, to crack close to one-quarter of the passwords of the 500 or so Forbes employees in the database," said Sophos' Paul Ducklin.

"Astonishingly, 73 Forbes staffers (more than one-eighth of the list) had chosen a password consisting of their company's name, Forbes, followed by zero to four digits. 1 and 123 were the most common suffixes.”

Three online articles were defaced by the SEA as proof it carried out the database raid, and at the time of writing, Forbes' blog sites remain out of action. ®

Intelligent flash storage arrays

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Home Office: Fancy flogging us some SECRET SPY GEAR?
If you do, tell NOBODY what it's for or how it works
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Syrian Electronic Army in news site 'hack' POP-UP MAYHEM
Gigya redirect exploit blamed for pop-rageous ploy
prev story

Whitepapers

Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Driving business with continuous operational intelligence
Introducing an innovative approach offered by ExtraHop for producing continuous operational intelligence.