Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can someone clarify exactly what and from whom was stolen?


I haven't downloaded the dump files yet, but from what I can tell, their entire db was stolen. Meaning, customers' names, emails, addys, credit cards, etc. But most importantly, they were able to decrypt the customers' passwords back into plain text, too...


Hopefully specialforces.com will do a full disclosure to their customers immediately. Every second counts at this point...


Judging by all the bitcoin-exchange-related spam I received after the MtGox database was stolen, my guess is that even if they don't bother to, their competitors will happily notify their customers via email for them.


Did you read the pastebin text?

Line 30:

  "In reality, for the past few months, we have been in possession 
   of approximately 14,000 passwords and 8000 credit cards from 
   SpecialForces.com."
Line 36-37:

  "http://[redacted].gz  <- orders/addresses/ccs
   http://[redacted].txt  <- just the passwords"


This was just a hack of a random e-commerce site. They (like thousands of similar small businesses) sell equipment to police and weekend warriors.

The title is a bit misleading, the site had a "Secured by GoDaddy" logo on it, because the site had purchased its SSL certificate from GoDaddy and they throw the security logo thing in for free.

EDIT: My bad. They also paid the $4.99/month for the "Hacker Safe" logo.


Notice how they have 2 godaddy badges. The one of the right is the SSL one, as you're describing. The one on the left however, actually reads: "Hacker Proof... Scanned by...".



GoDaddy claims to offer website security as a service:

http://www.godaddy.com/security/website-security.aspx

Under the "Common Threats" tab, they claim to find "spyware, back doors, SQL injection opportunities and cross-site scripting (XSS) holes".

They also imply that they check input fields "properly", since "When fields aren't checked properly, hackers can insert code that exposes everything in your database."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: