Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

February 14th, 2011, 08:48 GMT · By

Rootkit.com Compromise Poses Risks to Other Sites

SHARE:

Adjust text size:


Rootkit.com cracked passwords posted online
Enlarge picture
People who analyzed the recently leaked rootkit.com user database warn that the compromise also has implications for accounts on other sites due to password reuse.

A week ago, the Anonymous collective hacked into the systems of a security firm called HBGary which threatened to expose its high-ranking members.

The group leaked tens of thousands of corporate emails and other confidential information, along with the user database of rootkit.com, a research website maintained by HBGary founder and CEO Greg Hoglund.

Because the passwords in the database were hashed with the vulnerable RC5 algorithm they were relatively trivial to crack.

Dazzlepod managed to recover the passwords for 64,489 accounts out of the nearly 81,000 in the database using the popular John the Ripper password cracking software.

"By randomly putting the passwords to test, many appear to be reused by the same user elsewhere on sites presumably of lower value to the user, e.g. Facebook, Twitter, forum sites, secondary email accounts, etc.," Dazzlepod warns.

For example, running the cracked credentials through the mechanize tool against Twitter resulted in 225 matches for @gmail.com addresses alone.

In reality the number is probably much higher and the problem extends to other websites. A few hundred accounts are more than enough to launch a mass spam or malware distribution campaign, and it wouldn't be unusual if this was to happen.

Following the Gawker hack in December and the leak of its 1.3-million-strong user database, large spam attacks using the exposed credentials were mounted on Twitter.

A recent data analysis that put the rootkit.com database against the Gawker one, determined that there was a password reuse rate of at least 31% between the two.

People who had a rootkit.com account and used a password common to other places are strongly advised to change it as soon as possible.

TELL US WHAT YOU THINK:

3,265 hits · 3 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Real-World Data Analysis Reveals Very High Password Reuse Rate

Anonymous Hacks into Security Firm's Network and Steals Confidential Data

Gawker Accounts Database Analysis Reveals Poor Password Habits

Twitter Fast-Spreading Spam Attack Linked to Gawker Compromise

READER COMMENTS:


Comment #1 by: aaron on 15 Feb 2011, 17:05 UTC reply to this comment

The number 225 is incorrect, from dazzlepod.com/rootkit, "..mechanize found at least 648 accounts using @gmail.com alone can be used to login to Twitter..", I believe the number keeps increasing as the program finds more accounts.

Comment #1.1 by: dazzlepod on 18 Feb 2011, 07:28 GMT

Yes, we perform the mechanize driven test against random selection of rootkit.com accounts with @gmail.com with approximately 1 account every 2 seconds. To date, we have uncovered over 1200 email/password pairs that can successfully login to Twitter.


Comment #2 by: TT on 09 Mar 2011, 00:51 UTC reply to this comment

what kind of legal action can you take on this matter?

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM