Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

June 28th, 2011, 12:53 GMT · By

Hacker Group Publishes Stolen PayPal and MySpace Credentials

SHARE:

Adjust text size:


150 MySpace and 50 PayPal accounts exposed online
Enlarge picture
A group of hackers has leaked tens of MySpace and PayPal login credentials which were allegedly captured by sniffing packets on open wireless networks.

Called D3V29, the group has openly declared its affiliation with Operation Anti-Security (AntiSec), the hacking campaign originally started by LulzSec and carried forward by Anonymous.

D3V29 posted the "dumps" on pastebin.com and advertised the links on its Twitter feed. The group told SC Magazine AU that it obtained the credentials by scanning public wireless networks in restaurants and stores with self-made software.

The software is described as batch code that connects to the network and intercepts login data. The description resembles that of ARP spoofing attacks.

There is one problem with this theory though — PayPal uses HTTPS for login, and so do most modern websites. This ensures that passwords are not transmitted in plaintext form.

Another type of attack that results in account compromise and is possible over open wireless networks is known as sidejacking and involves capturing the session cookies that sent along with web requests.

Websites that do not employ full-session HTTPS leave their users exposed to this type of attack, however, sidejacking has nothing to do with passwords either.

Attackers can use the captured cookies to hijack active sessions. This would give them temporary access to the corresponding accounts, but they still wouldn't get plaintext passwords like those leaked by D3V29.

It is more likely that these hackers used phishing or a trojan to steal the login credentials than a WiFi-based attack. However, regardless of the method used, PayPal and MySpace should react immediately by suspending the accounts or resetting their passwords in order to prevent further abuse.

As we previously said, the fact that LulzSec disbanded and its members merged back into Anonymous to keep a lower profile, doesn't mean that the indiscriminate attacks and leaking of user information will stop.

TELL US WHAT YOU THINK:

1,785 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Indian Groupon Subsidiary Exposes Customer Emails and Passwords

LulzSec Leaked Passwords Stolen from Writerspace

LulzSec Leaks over 60K Email Credentials

LulzSec Leaks Over 26K New Emails and Passwords

Android App Can Hijack Web Sessions over Protected Wireless Networks

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM