4 ms·
Looks like they used SQL injection to get passwords and then used those passwords to access the servers.
by ripter 13y ago
Looks like they used SQL injection to get passwords and then used those passwords to access the servers.
- rodolphoarruda 13y agoYeah, and that's from the application layer down to the DB layer. I wonder how they were able to pass through the other layers of the stack. I heck of a work, no wonder they'd spent "months" on it.
- sarreph 13y ago...crazy.
- acv 13y agoThe article says that they used the injection to get hashed login credentials. Did they then use a rainbow table to reverse the hashing?
- dgroves 13y agoPrecisely why hash(salt+password) is no longer sufficient. An HSM is require with keys known to nobody (backup HSM's locked in a safe) but the password hashing machine. In a nutshell it should be more like this: Hash(hsm_keys+salt+password) Of course all the usual things about entropy still apply, that string should be at least 256 bytes (256 bits of entropy is 32 bytes, so I am advocating much, much more), and that will likely only keep you safe until the next generation of ASIC computers are released.
- meowface 13y agoThere are a wide myriad of ways that plaintext can be derived from password hashes. Rainbow tables are an option if they're not salted; otherwise the attackers likely had access to fairly significant computing power (considering the amount of money they were raking in) to perform typical dictionary + bruteforce attacks on them.