📜 ⬆️ ⬇️

More than 25 million accounts of mail.ru gaming forums have been stolen by intruders

image


As a result of exploiting the SQL-injection vulnerability in old versions of vBulletin, unknown attackers managed to steal data on 12.8 million cfire.mail.ru accounts, 8.9 million parapa.mail.ru accounts and 3.2 million tanks.mail.ru accounts.


Leakage data is published on the LeakedSource website, including information on the number of decrypted password hashes:


Subdomains belonging to mail.ru were hacked in August of 2016.

Specifically they are:
cfire.mail.ru - 12,881,787 users, 6,226,196 passwords cracked at the time of this post.
parapa.mail.ru (main game) - 5,029,530 users, 3,329,532 passwords cracked at the time of this post.
parapa.mail.ru (forums) - 3,986,234 users, 2,907,572 passwords cracked at the time of this post.
tanks.mail.ru - 3,236,254 users, 0 passwords cracked at the time of this post.

As a result of the hacking, the attackers obtained data on user names, dates of birth, email addresses and encrypted passwords. Some databases contained users ’IP addresses and phone numbers.


According to the LeakedSource leak aggregator, some passwords were encrypted using the md5 algorithm, which in current realities is not a reliable protection.


Top 20 passwords from decrypted hashes:


roomPasswordamount
one123456789263.347
212345678201.977
312345689.756
four123456789089.497
fiveqwertyuiop32.584
612312312331.268
71111111130.827
eight1q2w3e4r5t30.087
91q2w3e4r27.399
ten98765432123.387
elevenqazwsxedc20.748
12qweasdzxc19.039
131234qwer18.434
141234432117 488
1511111116.372
sixteen8888888814.651
171qaz2wsx14.487
18123455432114.262
nineteenqwertyui14.187
2012312313.892

Users do not change their habits and use simple passwords on most services. The top 20 passwords in terms of frequency of use roughly coincide in the database of the “leakage” passwords of 100 million Vkontakte users.


Subdomains of * .mail.ru (games, many services, etc.) are not directly related to the functionality of the mail.ru mail service, and are not related to it except for the mail address.


')

Source: https://habr.com/ru/post/308466/


All Articles