Welcome to Welcome to DNF.com™ - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars

If you are new to domains and looking to buy, sell and learn about domains then you have come to the right place. DNForum is the largest domain name community on the internet and continues to grow every day. There are over 105,000 domainers on DNForum doing everything from buying domains, selling domains, learning about domains and discussing domains. Take a minute and Register.

Register Today on DNForum IT'S FREE!

Results 1 to 18 of 18
  1. #1
    d.i.y
    vital's Avatar
    Join Date
    Jan 2011
    Location
    Prague
    Posts
    392
    Country

    Czech Republic
    DNF$
    2,527
    Bank
    21,128
    Total DNF$
    23,655
    Donate  

    LinkedIn hacked?

    whats?! 6 500 000 passwords leaked... you should change your pass
    Theo likes this.
    Disclaimer: all offers made are valid for next 24 hours
    loremipsumgenerator.com
    quick CSS gradient guide

  2. #2
    Country hopper
    katherine's Avatar
    Join Date
    Jul 2005
    Location
    DMZ
    Posts
    8,229
    Country

    Iceland
    DNF$
    36,490
    Bank
    0
    Total DNF$
    36,490
    Donate  
    6 million SHA1 password hashes are now in the open.

  3. #3
    Moderator
    Biggie's Avatar
    Join Date
    Sep 2002
    Location
    96.net
    Posts
    14,565
    Blog Entries
    1
    Country

    United States
    DNF$
    58,377
    Bank
    0
    Total DNF$
    58,377
    Donate  
    i have no account there, but what could be gained from hack'n them... just to say it could done?
    Need A SedoPro Account PM Me * nev.org * pmm.org * svc.net * ispoof.com * umm.org * sop.net * qfm.net * upyo.com * vioz.com * uce.org * wta.net * eoso.com * Coming Soon: OrganicWineCompany.com

  4. #4
    Platinum Lifetime Member

    Join Date
    May 2011
    Posts
    79
    Country

    United States
    DNF$
    1,308
    Bank
    0
    Total DNF$
    1,308
    Donate  
    Thanks for the post. I ran out and changed my password and confirmed that there was a breach. Identity theft and loads of other stuff are what can be gained. There are people/companies that will pay big money for the information that could be gathered from these accounts.

  5. #5
    Bloody Hell
    Theo's Avatar
    Join Date
    Feb 2004
    Location
    USA
    Posts
    30,585
    Country

    United States
    DNF$
    7,938
    Bank
    0
    Total DNF$
    7,938
    Donate  
    Thanks for the heads up. The sad part is, I thought the email to change my password was spam.

    DomainGang.com - Domain News Done Right
    Acroplex - Web & Graphics Development
    Acro.net - Domain Investing Rants and Raves

  6. #6
    Country hopper
    katherine's Avatar
    Join Date
    Jul 2005
    Location
    DMZ
    Posts
    8,229
    Country

    Iceland
    DNF$
    36,490
    Bank
    0
    Total DNF$
    36,490
    Donate  
    Quote Originally Posted by biggedon View Post
    i have no account there, but what could be gained from hack'n them... just to say it could done?
    The linkedin DB must contain a lot of personal information so it's sensitive and acquisition of the data can facilitate identity theft for example.

    The problem is that people tend to use the same passwords for different sites, even their E-mail.
    Imagine the damage that can be done if your E-mail is compromised

    In this case the passwords were hashed but not salted, so the non-complex passwords can be derived quite quickly. The user names are not available at this time but the hackers must have more than just the hashed passwords.
    Every breach is a reminder to use hard to guess passwords (with special characters too) and not to reuse them
    Last edited by katherine; 06-06-2012 at 01:43 PM. Reason: typo
    Theo likes this.

  7. #7
    þórr mjǫlnir
    draggar's Avatar
    Join Date
    Dec 2007
    Location
    South Florida
    Posts
    13,471
    Country

    Czech Republic
    DNF$
    2,166
    Bank
    134,005
    Total DNF$
    136,171
    Donate  
    Quote Originally Posted by biggedon View Post
    i have no account there, but what could be gained from hack'n them... just to say it could done?
    What's the point of the dozens to thousands of hack attempts on my sites (brute force admin login attempts)? Seriously, what, they're going to change the content?

    Luckily, LinkedIn was one site that used an older password system for me .
    Save the wolves - join The Wolf Army today!
    Please follow the rules or suffer the wrath of Thor's Hammer.

  8. #8
    Country hopper
    katherine's Avatar
    Join Date
    Jul 2005
    Location
    DMZ
    Posts
    8,229
    Country

    Iceland
    DNF$
    36,490
    Bank
    0
    Total DNF$
    36,490
    Donate  
    Quote Originally Posted by draggar View Post
    What's the point of the dozens to thousands of hack attempts on my sites (brute force admin login attempts)? Seriously, what, they're going to change the content?
    In general, it's bored and untalented script kiddies scanning IP addresses at random, with no particular target in sight. Then they will exploit the first vulnerable server. Perhaps they will use it to host illegal contents, send spam, or mount further attacks on third parties and cover their tracks. Or they will just boast about their hacker skills on some forum
    It's often just about ego and gratification.
    Theo likes this.

  9. #9
    þórr mjǫlnir
    draggar's Avatar
    Join Date
    Dec 2007
    Location
    South Florida
    Posts
    13,471
    Country

    Czech Republic
    DNF$
    2,166
    Bank
    134,005
    Total DNF$
    136,171
    Donate  
    Quote Originally Posted by katherine View Post
    In general, it's bored and untalented script kiddies scanning IP addresses at random, with no particular target in sight. Then they will exploit the first vulnerable server. Perhaps they will use it to host illegal contents, send spam, or mount further attacks on third parties and cover their tracks. Or they will just boast about their hacker skills on some forum
    It's often just about ego and gratification.
    No, this is just people trying to log into the admin panel on wordpress sites (one site was getting a brute force this morning while I left for work).

    You really can't do anything if you do log in other than change content. Yeah, maybe to post spam but that's about it.

    As fro untalented script kiddies, you forgot immature, too.
    Save the wolves - join The Wolf Army today!
    Please follow the rules or suffer the wrath of Thor's Hammer.

  10. #10
    www.ehot.net
    Stian's Avatar
    Join Date
    Jan 2007
    Location
    EHOT.net
    Posts
    7,646
    Country

    Norway
    DNF$
    7,189
    Bank
    0
    Total DNF$
    7,189
    Donate  
    Quote Originally Posted by draggar View Post
    No, this is just people trying to log into the admin panel on wordpress sites (one site was getting a brute force this morning while I left for work).
    Grab a free plugin called 'Limit Login Attempts' and Wordpress will block any IP that fails login x amount of times (opposed to WP's unlimited login attempts which opens up for bruteforcing).

    It will still be possible to attack using multiple proxies, but most of those exploitation bots are dumb and you should be able to filter out most/all of the bf attempts with this plugin.

  11. #11
    þórr mjǫlnir
    draggar's Avatar
    Join Date
    Dec 2007
    Location
    South Florida
    Posts
    13,471
    Country

    Czech Republic
    DNF$
    2,166
    Bank
    134,005
    Total DNF$
    136,171
    Donate  
    Already got that - they just wait out the lockout period and try it again.

    Every WP site of mine gets about 10-15 a day but some sites (political mainly) can get hundreds a day. Oddly, recently one site (informational, non political, and hasn't been updated in a while) got about 15,000 the other day. Yeah, Outlook loved getting all those logs in! I guessI missed that one - it got installed.
    Save the wolves - join The Wolf Army today!
    Please follow the rules or suffer the wrath of Thor's Hammer.

  12. #12
    www.ehot.net
    Stian's Avatar
    Join Date
    Jan 2007
    Location
    EHOT.net
    Posts
    7,646
    Country

    Norway
    DNF$
    7,189
    Bank
    0
    Total DNF$
    7,189
    Donate  
    Quote Originally Posted by draggar View Post
    Already got that - they just wait out the lockout period and try it again.

    Every WP site of mine gets about 10-15 a day but some sites (political mainly) can get hundreds a day. Oddly, recently one site (informational, non political, and hasn't been updated in a while) got about 15,000 the other day. Yeah, Outlook loved getting all those logs in! I guessI missed that one - it got installed.
    Hmm weird.. I don't have a lot of WP sites, but the two I got hasn't had any attempts yet that I'm aware of. They're not exactly high traffic yet, so that might explain why they're not a target. You could really set the lockout time to several days, then it's basically impossible to bruteforce the site (it may take months/years, but you will change the password in between so it's no use).

  13. #13
    þórr mjǫlnir
    draggar's Avatar
    Join Date
    Dec 2007
    Location
    South Florida
    Posts
    13,471
    Country

    Czech Republic
    DNF$
    2,166
    Bank
    134,005
    Total DNF$
    136,171
    Donate  
    The site that had 15,000 attempts gets fewer than 30 visitors a month - highest ever was 50. I guess they think it is abandoned and can change the content and no one will notice?
    Save the wolves - join The Wolf Army today!
    Please follow the rules or suffer the wrath of Thor's Hammer.

  14. #14
    silentg's Avatar
    Join Date
    Feb 2010
    Posts
    2,536
    Country

    Canada Follow silentg On Twitter Add silentg on Facebook
    DNF$
    9,710
    Bank
    0
    Total DNF$
    9,710
    Donate  
    Same hacker stole 1.5 million passwords from eHarmony > http://mashable.com/2012/06/06/eharm...swords-stolen/

  15. #15
    www.ehot.net
    Stian's Avatar
    Join Date
    Jan 2007
    Location
    EHOT.net
    Posts
    7,646
    Country

    Norway
    DNF$
    7,189
    Bank
    0
    Total DNF$
    7,189
    Donate  
    Quote Originally Posted by draggar View Post
    The site that had 15,000 attempts gets fewer than 30 visitors a month - highest ever was 50. I guess they think it is abandoned and can change the content and no one will notice?
    Wow!

    Yeah, or use it for malware Hosting etc. Do you keep WP and all plugins updated?

  16. #16
    þórr mjǫlnir
    draggar's Avatar
    Join Date
    Dec 2007
    Location
    South Florida
    Posts
    13,471
    Country

    Czech Republic
    DNF$
    2,166
    Bank
    134,005
    Total DNF$
    136,171
    Donate  
    I try to - whenever I log into the admin panel I check and update anything and everything that needs it. I'm just chalking it up to major a-holes.

    Plus, what's the worst they'll do? If they crash the entire site I'll know and have the site wiped and restored within 24 hours.
    Save the wolves - join The Wolf Army today!
    Please follow the rules or suffer the wrath of Thor's Hammer.

  17. #17
    www.ehot.net
    Stian's Avatar
    Join Date
    Jan 2007
    Location
    EHOT.net
    Posts
    7,646
    Country

    Norway
    DNF$
    7,189
    Bank
    0
    Total DNF$
    7,189
    Donate  
    Quote Originally Posted by draggar View Post
    I try to - whenever I log into the admin panel I check and update anything and everything that needs it. I'm just chalking it up to major a-holes.

    Plus, what's the worst they'll do? If they crash the entire site I'll know and have the site wiped and restored within 24 hours.
    True, they can't do too much.

  18. #18
    d.i.y
    vital's Avatar
    Join Date
    Jan 2011
    Location
    Prague
    Posts
    392
    Country

    Czech Republic
    DNF$
    2,527
    Bank
    21,128
    Total DNF$
    23,655
    Donate  
    We are currently investigating the leak of some Last.fm user passwords. This follows recent password leaks on other sites, as well as information posted online. As a precautionary measure, we're asking all our users to change their passwords immediately.
    Please log in to Last.fm and change your password on your settings page.
    hmmm, they just leak and leak...
    Disclaimer: all offers made are valid for next 24 hours
    loremipsumgenerator.com
    quick CSS gradient guide

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Domain name forum recommended by Domaining.com