Well-known web comic XKCD been hacked, about 56 million users data was leaked

XKCD is the most popular foreign popular web comic site, its annoying technical and other romantic humor, mathematics, science and language comics full load is known, it has suffered a data breach exposing its forum user data.

XKCD security personnel: It is strongly recommended that affected users to change their passwords XKCD, and any other online account password to re-use the same password immediately. XKCD founded by American writer Randall Munroe in 2005, it is a popular web comic, focusing on science and technology, science and the Internet culture, which is different from the stated theme, mathematics, and science programming jokes life and love.

According to security researcher Troy Hunt (Troy Hunt) warning the company of this incident, hackers approximately 560,000 user names, e-mail and IP addresses, and hashed password. However, the leaked data is actually discovered by security researchers and data analysts. As of this writing, XKCD has canceled its forum and issued a brief notice on its home page, urged its users to change their passwords immediately.

xkcd Forum Index was hung hacker "Oriental Alliance hacker", by Chinese translation, identified as "Eastern Union" meaning hackers. xkcd forums responsible person suspected of Chinese "hackers" as the organization of the Eastern League, but its founder Guo Shenghua been negative. Currently xkcd forums offline. Headquarters has received a warning, PHPBB user table section xkcd forums appear in the centralized data leakage. Data including user name, email address, salted, hashed password, and in some cases, as well as the IP address when registering.

As mentioned above, XKCD use phpBB, which is a free open source forum software PHP programming and built-in software. However, it is unclear whether the use XKCD susceptible to security vulnerabilities of the old version of the forum software, phpBB or an attacker using any previously undetected defects to extract data without authorization. In addition, even if the use XKCD run on a more secure hash algorithm BCRYPT phpBB 3.1 and later, early users of XKCD forum password may also be carried out by older, less secure MD5 hashing methods encryption. (Please share)

 

Guess you like

Origin www.cnblogs.com/bjzb/p/11457737.html