This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here
by Alastair Stevenson
12 Jul 2012
Hackers claim to have breached Yahoo's security, posting the alleged login details of over 450,000 users.
The attack reportedly targeted the company's Yahoo Voices platform with a union-based SQL injection technique - a form of attack that tries to trick a SQL database to run a string containing malicious code.
The hackers posted over 453,000 alleged login credentials to the D33D Company website as proof of the breach, claiming the attack was intended to be a wake up call for Yahoo.
"We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat," the group said.
"There have been many security holes exploited in webservers belonging to Yahoo that have caused far greater damage than our disclosure. Please do not take them lightly. The subdomain and vulnerable parameters have not been posted to avoid further damage."
Yahoo told V3 that it was investigating the hackers' post and encouraged users to change passwords regularly.
"At Yahoo we take security very seriously and invest heavily in protective measures to ensure the security of our users and their data across all our products. We are currently investigating the claims of a compromise of Yahoo user IDs," said a Yahoo spokesman.
"We encourage users to change their passwords on a regular basis and also familiarise themselves with our online safety tips at security.yahoo.com."
Prior to the hackers post, question and answer site Formspring confirmed it had disabled its users passwords after around 420,000 hashed passwords claiming to belong to the site were posted to a security forum.
The breaches come after several high-profile password thefts in June with LinkedIn and Last.fm both affected.
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Which productivity tools do you use for work?
V3 pits Sony's rugged flagship against Apple's premier handset
Updating your subscription status
Connect with V3.co.uk
It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model
BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs
Business Analyst - Financial Services - required for...
QlikView Consultant / QlikView Developer required for...
Business Intelligence Developer (SSIS SSAS SSRS) required...
SharePoint Developer (Senior) required for a MS Gold...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree