“Almost every account password was cracked, thanks to the company’s poor security practices, ” reports ZDNet — even for “deleted” accounts. An anonymous reader quotes their article: The hack includes 339 million accounts from AdultFriendFinder.com, which the company describes as the “world’s largest sex and swinger community [and] also includes over 15 million “deleted” accounts that weren’t purged from the databases. On top of that, 62 million accounts from Cams.com, and 7 million from Penthouse.com were stolen, as well as a few million from other smaller properties owned by the company. The data accounts for two decades’ worth of data from the company’s largest sites, according to breach notification LeakedSource, which obtained the data… The three largest site’s SQL databases included usernames, email addresses, and the date of the last visit, and passwords, which were either stored in plaintext or scrambled with the SHA-1 hash function, which by modern standards isn’t cryptographically as secure as newer algorithms. The attack apparently coincides with the discovery of “a local file inclusion flaw on the AdultFriendFinder site, which if successfully exploited could allow an attacker to remotely run malicious code on the web server. ” Ironically, Friend Finder Networks doesn’t even own Penthouse.com anymore. They sold the site to a new owner last February. Read more of this story at Slashdot.
View post:
Hack Exposes 412 Million Accounts on AdultFriendFinder Sites
An anonymous reader writes: “Wow, dude I did not even know we were fighting, ” Wix CEO Avishai Abrahami posted on the company’s blog Saturday — responding to WordPress creator Matt Mullenweg, who on Friday accused Wix of stealing their code. “The claim is that the Wix mobile apps distribute GPL code and aren’t themselves GPL, so they violate the license, ” Mullenweg wrote. Abrahami argued that “Everything we improved there or modified, we submitted back as open source, ” adding “we will release the app you saw as well… ” Mullenweg responded “It appears you and [lead engineer] Tal might share a misunderstanding of how the GPL works, ” ultimately adding “software licensing can be tricky and many people make honest mistakes.” Wix had also argued they’re giving back to the open source community by listing 224 public projects on their GitHub page. “Thank you for the offer to use them, ” Mullenweg responded. “If we do, we’ll make sure to follow the license you’ve put on the code very carefully.” Read more of this story at Slashdot.