Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

April 26th, 2012, 08:41 GMT · By

BLOG

Hackers Leak Admin Credentials from University of Massachusetts Site (Updated)

SHARE:

Adjust text size:


Hackers prove that the Political Economy Research Institute site of the University of Massachusetts contains dangerous security holes Enlarge picture - Hackers prove that the Political Economy Research Institute site of the University of Massachusetts contains dangerous security holes
Hackers part of Team Dig7tal found an SQL Injection vulnerability in the Political Economy Research Institute site of the University of Massachusetts. To prove that it’s not something to joke about, they leaked some information from the website’s databases.

The information includes database structure, but also a number of 11 credential sets with administrator email addresses, usernames and password hashes.

The worrying part is that the hashes are MD5 and can be decrypted in a matter of seconds.

Hopefully, University of Massachusetts representatives have noticed the breach and acted on securing the site. Otherwise, an ill-intended individual (now that the passwords are out it doesn’t even have to be a hacker) can easily gain access to the site and cause some serious damage.

Team Dig7tal has also made available the vulnerable URL that allowed them to gain access to the university’s systems.

As usual, since there's sensitive information involved, we will not provide a link to the data leak.

Update. University of Massachusetts representatives contacted us to reveal that the security hole highlighted by the hackers has been addressed.

TELL US WHAT YOU THINK:

1,063 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Team Dig7tal Hackers Leak Data from Harvard University's SEAS

Los Alamos National Lab, Photography Masters Cup Sites Hacked

Dejen Aviation Industry and University of Nebraska-Lincoln Sites Breached

Hackers Expose XSS Flaws in Vatican, Humboldt and NASA Sites

Team Dig7tal Prove SQL Injection Flaw in Rajkot Municipal Corporation Site

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM