5 ms·
Can someone clarify exactly what and from whom was stolen?
by elbac 15y ago
Can someone clarify exactly what and from whom was stolen?
- mschonfeld 15y agoI haven't downloaded the dump files yet, but from what I can tell, their entire db was stolen. Meaning, customers' names, emails, addys, credit cards, etc. But most importantly, they were able to decrypt the customers' passwords back into plain text, too...
- sycr 15y agoHopefully specialforces.com will do a full disclosure to their customers immediately. Every second counts at this point...
- sneak 15y agoJudging by all the bitcoin-exchange-related spam I received after the MtGox database was stolen, my guess is that even if they don't bother to, their competitors will happily notify their customers via email for them.
- dsl 15y agoThis was just a hack of a random e-commerce site. They (like thousands of similar small businesses) sell equipment to police and weekend warriors. The title is a bit misleading, the site had a "Secured by GoDaddy" logo on it, because the site had purchased its SSL certificate from GoDaddy and they throw the security logo thing in for free. EDIT: My bad. They also paid the $4.99/month for the "Hacker Safe" logo.
- mschonfeld 15y agoNotice how they have 2 godaddy badges. The one of the right is the SSL one, as you're describing. The one on the left however, actually reads: "Hacker Proof... Scanned by...".
- burgerbrain 15y agohttp://www.specialforces.com/catalog/view/theme/sfg/image/icon_hacker_proof.gif http://www.specialforces.com/catalog/view/theme/sfg/image/ic... Stunning.
- Terretta 15y agoGoDaddy claims to offer website security as a service: http://www.godaddy.com/security/website-security.aspx http://www.godaddy.com/security/website-security.aspx Under the "Common Threats" tab, they claim to find "spyware, back doors, SQL injection opportunities and cross-site scripting (XSS) holes". They also imply that they check input fields "properly", since "When fields aren't checked properly, hackers can insert code that exposes everything in your database."
- biot 15y agoDid you read the pastebin text? Line 30: "In reality, for the past few months, we have been in possession of approximately 14,000 passwords and 8000 credit cards from SpecialForces.com." Line 36-37: "http://[redacted].gz <- orders/addresses/ccs http://[redacted].txt <- just the passwords"