{"id":3015,"date":"2010-12-15T09:27:37","date_gmt":"2010-12-15T09:27:37","guid":{"rendered":"https:\/\/www.darknet.org.uk\/?p=3015"},"modified":"2015-09-09T19:37:21","modified_gmt":"2015-09-09T11:37:21","slug":"fbi-investigating-gawker-media-user-database-password-ownage","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2010\/12\/fbi-investigating-gawker-media-user-database-password-ownage\/","title":{"rendered":"FBI Investigating Gawker Media User Database Password Ownage"},"content":{"rendered":"

After the non-stop action with WikiLeaks<\/a> last week, the big news this week is the hack carried out on Gawker Media which exposed their users e-mail addresses and passwords. More than 200,000 password hashes (very lightly encrypted with DES) and e-mail combos can be downloaded on-line as a torrent file.<\/p>\n

Now this has had some epic fall-out as we all know many people use the same passwords for all their online services, so a whole bunch of Twitter accounts were owned and used for spamming Acai berries<\/a> – causing Twitter to block\/delete these accounts and reset a whole lot of passwords.<\/p>\n

Now if you search through the files, there are a whole lot of major corporate domains inside – including some government organizations. This is the fact that is obviously worrying to the FBI and is leading them to carry out an investigation.<\/p>\n

The FBI confirmed to PC World that it is investigating the recent intrusion by a group of hackers into Gawker Media’s servers last weekend. The hack exposed more than 200,000 reader e-mail addresses and passwords, and the data is now circulating online as a peer-to-peer torrent file. An FBI representative declined to comment further about the ongoing investigation; however, Gawker Media founder and CEO Nick Denton was scheduled to meet with federal authorities on Monday, according to The New York Post .<\/p>\n

On Sunday, an online hacker collective calling itself Gnosis broke into the servers of Gawker Media, which owns a variety of popular online blogs including Deadspin, Fleshbot, Gawker, Gizmodo, Jezebel, io9, Jalopnik, Kotaku and Lifehacker. The hackers obtained the e-mail addresses and passwords for the company’s employees, and the source code for Gawker Media’s content management system. Gnosis hackers also obtained the login credentials for readers who were registered to leave comments on Gawker Media websites.<\/p>\n

Gawker Media said most user login information was encrypted, but Gnosis managed to crack the credentials for more than 200,000 accounts. The exposed login information is now part of a data dump contained in a torrent file available on peer-to-peer file sharing networks. <\/p><\/blockquote>\n

It’s a pretty serious breach as Gawker is one of the major on-line media owners and their network reach is wide. 200,000 accounts with exposed passwords is not a small number and do remember just because people aren’t tech savvy (use weak passwords) it doesn’t mean they don’t hold some high position in some huge MNC.<\/p>\n

There’s a big debate going on at Hacker News<\/a> too about the ethics of e-mailing all the users in the file to notify them their passwords may have been breached. Apparently some people are already doing it, and other are writing scripts to extract the e-mail addresses and notify everyone to ensure no-one gets left behind.<\/p>\n