As a result of exploiting the SQL-injection vulnerability in old versions of vBulletin, unknown attackers managed to steal data on 12.8 million cfire.mail.ru accounts, 8.9 million parapa.mail.ru accounts and 3.2 million tanks.mail.ru accounts.
Leakage data is published on the LeakedSource website, including information on the number of decrypted password hashes:
Subdomains belonging to mail.ru were hacked in August of 2016.
Specifically they are:
cfire.mail.ru - 12,881,787 users, 6,226,196 passwords cracked at the time of this post.
parapa.mail.ru (main game) - 5,029,530 users, 3,329,532 passwords cracked at the time of this post.
parapa.mail.ru (forums) - 3,986,234 users, 2,907,572 passwords cracked at the time of this post.
tanks.mail.ru - 3,236,254 users, 0 passwords cracked at the time of this post.
As a result of the hacking, the attackers obtained data on user names, dates of birth, email addresses and encrypted passwords. Some databases contained users ’IP addresses and phone numbers.
According to the LeakedSource leak aggregator, some passwords were encrypted using the md5 algorithm, which in current realities is not a reliable protection.
Top 20 passwords from decrypted hashes:
room | Password | amount |
---|---|---|
one | 123456789 | 263.347 |
2 | 12345678 | 201.977 |
3 | 123456 | 89.756 |
four | 1234567890 | 89.497 |
five | qwertyuiop | 32.584 |
6 | 123123123 | 31.268 |
7 | 11111111 | 30.827 |
eight | 1q2w3e4r5t | 30.087 |
9 | 1q2w3e4r | 27.399 |
ten | 987654321 | 23.387 |
eleven | qazwsxedc | 20.748 |
12 | qweasdzxc | 19.039 |
13 | 1234qwer | 18.434 |
14 | 12344321 | 17 488 |
15 | 111111 | 16.372 |
sixteen | 88888888 | 14.651 |
17 | 1qaz2wsx | 14.487 |
18 | 1234554321 | 14.262 |
nineteen | qwertyui | 14.187 |
20 | 123123 | 13.892 |
Users do not change their habits and use simple passwords on most services. The top 20 passwords in terms of frequency of use roughly coincide in the database of the “leakage” passwords of 100 million Vkontakte users.
Subdomains of * .mail.ru (games, many services, etc.) are not directly related to the functionality of the mail.ru mail service, and are not related to it except for the mail address.
Source: https://habr.com/ru/post/308466/
All Articles