Data Storage Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Information for Data Storage Professionals
Commvault Simpana® 10
Protect, manage, access, and
realize the untapped value of data.

www.commvault.com
Wednesday, June 19th 
Introducing Simpana® 10 software
Home
Data Centers
Storage Solutions
Storage Networks
Data Storage Issues
Data Security
Enterprise I.T.
DST Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Data Security

6.5 Million LinkedIn Passwords May Be In Hands of Hackers

6.5 Million LinkedIn Passwords May Be In Hands of Hackers
June 6, 2012 11:41AM

Bookmark and Share
The reported LinkedIn password security breach is a good reminder to use a different password for each of the Web sites you access, said security analyst Neil Roiter. "The larger question to be answered is how the hackers were able to break in and steal the passwords," and what other LinkedIn user information was taken, Roiter said.

CommVault is a data and information management software company dedicated to providing organizations worldwide with a radically better way to manage data and information. Their unique Solving Forward philosophy allows them to deliver complete solutions with infinite scalability and unprecedented control over data and costs. Be among the first to experience Simpana 10 software. Click here now.

LinkedIn on Wednesday morning was still unable to confirm reports that 6.5 million user passwords had been exposed. But Sophos has discovered LinkedIn password information posted on a Russian hacker site.

"Although the data Relevant Products/Services which has been released so far does not include associated e-mail addresses, it is reasonable to assume that such information may be in the hands of the criminals," Graham Cluley, senior security analyst at Sophos, wrote in his blog. "Investigations by Sophos researchers have confirmed that the file does contain, at least in part, LinkedIn passwords."

How Did It Happen?

We caught up with Neil Roiter, research director at Corero Network Security, to get his reaction to the news. He told us the reported LinkedIn password breach is a good reminder to use a different password for each of the Web sites you access.

"The larger question to be answered is how the hackers were able to break in and steal the passwords, and what personally identifiable information, if any, also may have been stolen," Roiter said. "People will want assurances that LinkedIn will discover how they were breached, take appropriate steps to prevent a recurrence and review their overall security practices."

SQL Injection Likely

We turned to Dave Pack, director of LogRhythm Labs, to get additional insights about the reported breach. Without specific details of the attack, he told us it's difficult to determine exactly what could have been done to help protect Relevant Products/Services the sensitive data. However, he added, most database breaches are the result of a vulnerable Web application front-end being exploited using SQL injection.

"According to our research, it is extremely common for successful attackers to utilize automated SQL injection tools such as sqlmap or Havij," Pack said. "Such tools leave behind a log trail on the Web server Relevant Products/Services which at first glance makes the attack appear complex, but also makes it easy to detect."

Pack offered an example: By default these tools put their own names into the User Agent string of the http requests they make. He said user agent whitelisting and blacklisting can be used to make sure automated SQL injection tools are immediately identified if they try to do Web application reconnaissance or launch an attack.

"These tools put quite a bit of SQL syntax into URL parameters. Most Web applications have no legitimate need for SQL in the actual URLs. Alarming on this syntax along with encoded variations will detect both automated tool usage as well as manual Web application attacks," Pack said. (continued...)

1  |  2  |  Next Page >

 

Tell Us What You Think
Comment:

Name:

Advertisement



 Data Security
1. Spammers Target Victims by Phone
2. Yahoo, Apple Disclose Data Requests
3. Prism's Secret: Bigger Data Seizure
4. MS, Facebook Tell of Security Requests
5. Study: Gap in Cloud Perception, Reality


advertisement


 Most Popular Articles
1. New Nvidia Chip Boosts Citrix Graphics for Remote Workers
2. Verizon Enters Cloud Storage Wars with a Wisp
3. Dell Kills Its Public Cloud Effort, Will Offer Partner Marketplace
4. Blue Coat Beefs Up Big Data Security with Solera Buy
5. Security Alert: Beware of Tiffany Trojan on the Attack

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Is Cumulus OS Really a Cisco-Killer?
  Spammers Target Victims by Phone
  Yahoo, Apple Disclose Data Requests
  Prism's Secret: Bigger Data Seizure
  Samsung Offers Tiny, Superfast SSDs

 Technology Marketplace
BYOD & MDM
Forrester Research Inc., Report: BYOD from AT&T. Make everyone more efficient.
 
Cloud & Virtualization
Brocade technologies help enable the full benefits of virtualization.
 
Contact Centers
Unlock the potential in your people with Microsoft Dynamics
Improve your customer relationships with Microsoft Dynamics
 
Customer Service
Unlock the potential in your people with Microsoft Dynamics
Improve your customer relationships with Microsoft Dynamics
 
Data Centers
Your Next Generation Data Center Is Here! Vblock™ Systems from VCE
 
Data Security
Simpana® 10 software: an exponential leap forward
 
Data Storage
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Hardware
Panasonic Toughbook® mobile computers are built to keep you running.
 
Enterprise Software
Simpana® 10 software: an exponential leap forward
 
Hardware
The best document scanner for you? Try KODAK's scanner selector
 
Innovation
The best document scanner for you? Try KODAK's scanner selector
 
Laptops & Tablets
Panasonic Toughbook® mobile computers are built to keep you running.
 
Network Security
Brocade makes it easier to deploy, manage, and scale networks.
 
Navigation
Data Storage Today
Home/Top News | Data Centers | Storage Solutions | Storage Networks | Data Storage Issues | Data Security | Enterprise I.T.
DST Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 Data Storage Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.