How RockYou interprets hack of millions of its accounts

December 16, 2009 - 7:28am | Fraud | News |
| More
  
How RockYou interprets hack of millions of its accounts

RockYou, social app creator, notified 32 million of its users that their usernames and passwords may have been compromised by hackers who broke into the company’s older widgets.


RockYou chief technology officer Jia Shen said in an interview the company was notified of the SQL injection attack against RockYou.com last week by security company Imperva. As Shen reported, RockYou closed the site for its legacy applications, like slide show widgets, and secured them.


That took about a day. Thereafter, the company commenced poring through its databases to find any evidence of attack. RockYou’ representatives don’t know exactly what the hacker did in the attack.


In fact, a hacker posted some of the passwords and usernames that were allegedly stolen. Shen affirmed that those were legitimate passwords from RockYou’s databases, but he does not know exactly how many of them were stolen.


Shen admitted the passwords and usernames were stored in a database that was not encrypted, another no-no when it comes to security, that let hackers easily get access to them.


RockYou has started notifying users but has not finished yet. The company is advising users to change their passwords on the RockYou site and on any other sites where they’ve used the same username or password.

 




RSS feed Subscribe to Ecommerce Journal RSS feed

Tags keywords: hacking | Imperva | Password | RockYou | widget
-1 points

   Tell us what topics you want to be covered in the Ecommerce Journal?  
Image CAPTCHA
  


Comments on How RockYou interprets hack of millions of its accounts




Similar Articles on Ecommerce Journal by sections

FIGURES
PAYMENT SYSTEMS
BANKS
PLASTIC CARDS
ECOMMERCE-CHECKED
INVESTMENT INDUSTRY
FRAUD
ANALYTICS
OTHER THEMES
INTERVIEWS
LAW ASPECTS