Popular Posts
- 
The chances are you use the services of this company every month – but you might not have heard of Weebly. It is the web-hosting service...
 - 
Customers of hosting firm Fasthosts have seen a number of cloud services knocked over after system problems started last Thursday. In a ...
 - 
There are a lot of web hosting providers out there. If you are starting a first website or simply haven't faced this decis...
 - 
MyBroadband will host its annual Cloud and Hosting Conference on 25 May 2016 at the Gallagher Convention Centre in Midrand. Conference...
 - 
2017-12-17 Music of Sun, 17 Dec 20170 M.anifest to host fifth edition of Manifestivities on December 22 The annual musical conce...
 - 
To continue reading, we request you to support us by disabling your Ad Blocker In order to serve content on our website, we rely on adver...
 - 
Web hosting is one of the most important components to any great website. After all, without the right hosting package, you won't have...
 - 
Web.com is set to purchase all the available shares of Yodle, closing at the end of the first quarter of 2016 Yodle, based in New York C...
 - 
Greater Manchester, UK -- (SBWIRE) -- 12/02/2015 -- The attacks in Paris have changed the way many people see the world, not least because...
 - 
SANTA FE, NM --(Marketwired - February 29, 2016) - CrowdReviews.com, a platform for reviewing and ranking web hosting providers, has relea...
 
Blog Archive
- December (19)
 - November (25)
 - October (28)
 - September (26)
 - August (28)
 - July (31)
 - June (26)
 - May (27)
 - April (28)
 - March (30)
 - February (28)
 - January (31)
 - December (31)
 - November (30)
 - October (31)
 - September (29)
 - August (44)
 - July (56)
 - June (53)
 - May (54)
 - April (48)
 - March (55)
 - February (44)
 - January (3)
 - December (5)
 - November (5)
 - October (26)
 - September (25)
 - August (29)
 - July (26)
 - June (18)
 - September (1)
 
About Me
Powered by Blogger.
Total Pageviews
Thursday, October 29, 2015
Biggest Free Hosting Company Hacked; 13.5 Million Plaintext Passwords Leaked
                              The world's most popular Free Web Hosting company 000Webhost has suffered a major data breach, exposing more than 13.5 Million of its customers' personal records.      The stolen data includes usernames, passwords in plain text, email addresses, IP addresses and last names of around 13.5 Million of 000Webhost's customers.      According to a recent report published by Forbes, the Free Hosting service provider 000Webhost was hacked in March 2015 by an anonymous hacker.      In a post on its official Facebook page, the hosting company has acknowledged the data breach and posted the following statement:    "We have witnessed a database breach on our main server. A hacker used an exploit in old PHP version to upload some files, gaining access to our systems. Although the whole database has been compromised, we are mostly concerned about the leaked client information."    The stolen data was obtained by Troy Hunt, an Australian security researcher, who received the data from an anonymous source and also confirmed the authenticity of the data.    "By now there's no remaining doubt that the breach is legitimate and that impacted users will have to know," Hunt wrote in a blog post published Wednesday. "I'd prefer that 000webhost be the ones to notify [its customer] though."      000Webhost Ignored Data Breach Warnings Continuously      000Webhost web Hosting company repeatedly failed to pay attention to the early warnings by Troy Hunt and the Forbes journalist, but the company ultimately decided to ignore them.          The Web Hosting company did not even follow fundamental and standard security practices to ensure the security of its customers.      Data breaches are common these days. Just a few days back, we reported about a serious data breach at TalkTalk – the biggest phone and broadband provider in the UK that put the personal data of its 4 Million customers at risk.      But, What could a Security Breach lead to?    Severe damage to company's reputation   Loss of consumer trust   Thousands of dollars in penalties and fines   Personal data loss cost infinite   Temporary or Permanent Closure     Note: At the time of writing, 000webhost.com website is temporarily down.    What Should You Do Now?      For security reasons, the team at Free Hosting service has changed all customers' passwords to the random values and implemented encryption, without giving any direct notice to its affected customers.      That means, if you are one of those 13.5 Million 000webhost clients, then you need to follow the password reset process to generate a new password in order to access your account.      However, 000Webhost said: "We removed all illegally uploaded pages as soon as we became aware of the [data] breach. Next, we changed all the passwords and increased their encryption to avoid such mishaps in the future."      Storing customers passwords in plain text, ignoring early warnings, and then implementing encryption to prevent further damages.                                    About the author        Founder and Editor-in-Chief of 'The Hacker News'. Cyber Security Analyst, Information Security Researcher, Developer and Part-Time Hacker.                      Subscribe to Update  
Source: Biggest Free Hosting Company Hacked; 13.5 Million Plaintext Passwords Leaked
 
Want more Interesting Articles to your Inbox every Morning?.
Source: Biggest Free Hosting Company Hacked; 13.5 Million Plaintext Passwords Leaked
Subscribe to:
Post Comments
                    (Atom)
                
0 comments:
Post a Comment