Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - No Geek, no glory.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » November 2012 » Adobe confirms customer data breach

Adobe confirms customer data breach


Contributed by: Email on 11/15/2012 04:26 PM [ comments Comments ]


A hacker says that he managed to break into an Adobe server and copy the private credentials of approximately 150,000 users – including their names, email addresses and password hashes. To prove the attack, the intruder, who goes by the name of "ViruS_HimA" and claims to be from Egypt, has released extracts from his haul on the anonymous Pastebin text hosting service. The data includes details of users who the attacker has associated with Adobe, the US military and US government circles based on their email addresses.

Talking to security magazine Dark Reading, the hacker said that he managed to exploit an SQL injection hole for his attack. Apparently, he didn't encounter any obstacles such as a Web Application Firewall (WAF) that would filter out potentially dangerous HTTP requests. The attacker explained that he publicized the intrusion to highlight the vulnerabilities and motivate companies such as Adobe to enhance their security.

On its blog, Adobe has confirmed that an unauthorized third party successfully launched an attack on one of the company's customer databases. According to Adobe, the data originates from the Connectusers.com web site, which is a forum for customers of the Adobe Connect web conferencing service. The forum has since been temporarily suspended. Adobe says that the attacker didn't compromise the Adobe Connect service itself or any other areas of the company's web presence.

Adobe hasn't confirmed the attacker's claim that 150,000 user records were affected; neither has it provided any information on its password storage mechanisms. According to the hacker, Adobe's database contained MD5 hashes that can easily be cracked.

Update 15-11-12 14:55: According to security firm Sophos, the passwords were stored as unsalted MD5 hashes, which can easily be cracked quickly using modern CPU and GPU hardware. If the database extract turns out to be genuine, Adobe should have invested a little more effort in protecting the passwords of its users. The article "Storing passwords in uncrackable form" at The H Security explains how administrators can prevent passwords from being cracked this easily.






« Data breach as a result of NASA laptop theft · Adobe confirms customer data breach · Scotty beams data past firewalls and filters »




Comments
comments powered by Disqus

MajorGeeks.Com » News » November 2012 » Adobe confirms customer data breach

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition