[Cialug] Change your password on gawker sites

Josh More MoreJ at alliancetechnologies.net
Mon Dec 13 10:57:04 CST 2010


You can check if your account was compromised here:  http://www.google.com/fusiontables/DataSource?dsrcid=350662

Just do a search on the MD5 of your email address, instructions are in the right column of the spreadsheet.

I'm still looking for the raw dump of the stolen data so I can analyze it.

Josh More | Senior Security Consultant - CISSP, GIAC-GSLC, GIAC-GCIH
Alliance Technologies | www.AllianceTechnologies.net<http://www.alliancetechnologies.net>
400 Locust St., Suite 840 | Des Moines, IA 50309
515.245.7701 | 888.387.5670 x7701

Santa is Secure.  Are you?
http://www.alliancetechnologies.net/security/santa-2010

How are we doing? Let us know here:
http://www.alliancetechnologies.net/forms/alliance-technologies-feedback-survey
________________________________
From: cialug-bounces at cialug.org [cialug-bounces at cialug.org] on behalf of Matthew Nuzum [newz at bearfruit.org]
Sent: Monday, December 13, 2010 09:13
To: Central Iowa Linux Users Group
Subject: [Cialug] Change your password on gawker sites

Hi, if you use lifehacker, gizmodo or one of the other gawker websites your password may have been compromised (along with 1.5M others)

While initially denying the attack, Gawker has issued an apology to its users on all of its sites, urging them to change their passwords because of the attack. [1] If you have ever commented on any of the Gawker sites, we recommend that you go and change your password.

http://www.digitaltrends.com/computing/gawker-hacked-1-5-million-accounts-compromised/


[1] http://lifehacker.com/5712785/


1) How do I know if my password was hacked?
If you've registered an account on any Gawker Media web site (that includes Gawker, Gizmodo, Jalopnik, Jezebel, Kotaku, Lifehacker, Deadspin, io9, or Fleshbot), and you didn't log in using Facebook Connect, then it's best to assume that your username and password were included among the leaked data.

Passwords in our database are encrypted (i.e., not stored in plain text), but they're still potentially vulnerable to hackers. You should immediately change the password on your account, and if you used that password on any other web site, you should change your passwords on all of those accounts<http://lifehacker.com/5712785/#4> as well.

2) What if I logged in using Facebook Connect? Was my password compromised?
No. We never stored passwords of users who logged in using Facebook Connect.

--
Matthew Nuzum
newz2000 on freenode, skype, linkedin, identi.ca<http://identi.ca> and twitter

"An investment in knowledge pays the best interest." -Benjamin Franklin

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://cialug.org/pipermail/cialug/attachments/20101213/ab0b6152/attachment.htm 


More information about the Cialug mailing list