Welcome, Guest. Please login or register.
July 12, 2025, 01:07:30 PM

Login with username, password and session length

Search:     Advanced search
we're back, baby
*
Home Help Search Login Register
f13.net  |  f13.net General Forums  |  General Discussion  |  Topic: Gawker Hacked - Change your password 0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: Gawker Hacked - Change your password  (Read 4134 times)
NiX
Wiki Admin
Posts: 7770

Locomotive Pandamonium


on: December 12, 2010, 08:11:36 PM

Gawker was hacked by.. Anon I guess. Doesn't matter. They leaked everyones shit here. (Gawker response.)

Change your password. Hide yo kids, hide yo wife.
schild
Administrator
Posts: 60350


WWW
Reply #1 on: December 12, 2010, 08:13:35 PM

Guess I didn't have a gawker network account.
Yegolev
Moderator
Posts: 24440

2/10 WOULD NOT INGEST


WWW
Reply #2 on: December 12, 2010, 08:31:38 PM

Same.  What's gawker?

Why am I homeless?  Why do all you motherfuckers need homes is the real question.
They called it The Prayer, its answer was law
Mommy come back 'cause the water's all gone
Thrawn
Terracotta Army
Posts: 3089


Reply #3 on: December 12, 2010, 09:01:55 PM

What's gawker?

Also the amount of people using "password" as a password is both scary and hillarious.  But then again I don't use very complex passwords on sites that I'm not to worried if it would get stolen so I have less chance of forgetting them.  swamp poop

"Sometimes I think the surest sign that intelligent life exists elsewhere in the Universe is that none of it has tried to contact us."
MahrinSkel
Terracotta Army
Posts: 10859

When she crossed over, she was just a ship. But when she came back... she was bullshit!


Reply #4 on: December 12, 2010, 09:21:41 PM

Includes a lot of other sites, including Kotaku.

Gawker.com - New York City media and gossip
Gizmodo - Gadgets and technology
Kotaku - Video games
Jalopnik - Cars and automotive culture
Lifehacker - Productivity tips
Deadspin - Sports
Jezebel - Celebrity, Sex, Fashion for women
io9 - Science fiction
Fleshbot - Porn
Gawker.tv
Cityfile
Valleywag - San Francisco and Silicon Valley gossip

List by CityPages via LittleGreenFootballs.

--Dave

--Signature Unclear
angry.bob
Terracotta Army
Posts: 5442

We're no strangers to love. You know the rules and so do I.


Reply #5 on: December 12, 2010, 09:49:07 PM

Anyone reading those sites deserves to have their shit hacked. lol at people who actually log in to any of those shit sites, especially the gossip ones.

Wovon man nicht sprechen kann, darüber muß man schweigen.
Abagadro
Terracotta Army
Posts: 12227

Possibly the only user with more posts in the Den than PC/Console Gaming.


Reply #6 on: December 12, 2010, 09:56:45 PM

Looks to me like they only grabbed those who had real obvious passwords like "password" and "qwerty" and "asdfgh" rather than being some uber elite hack.

"As democracy is perfected, the office of president represents, more and more closely, the inner soul of the people. On some great and glorious day the plain folks of the land will reach their heart's desire at last and the White House will be adorned by a downright moron.”

-H.L. Mencken
Tale
Terracotta Army
Posts: 8567

sıɥʇ ǝʞıן sʞןɐʇ


Reply #7 on: December 13, 2010, 11:17:27 AM

Read about the extent of the Gawker hack and how poor their security is:

http://blogs.forbes.com/firewall/2010/12/13/the-lessons-of-gawkers-security-mess/
NiX
Wiki Admin
Posts: 7770

Locomotive Pandamonium


Reply #8 on: December 13, 2010, 12:03:17 PM

Looks to me like they only grabbed those who had real obvious passwords like "password" and "qwerty" and "asdfgh" rather than being some uber elite hack.

They only released the shitty ones. They have something like 1.3 million accounts dumped from the DB.

Quote
Will repeat one last time: there are torrents out there with passwords.

Three folders:
"Dumb_passwords.txt" which are, as the file says, dumb passwords (same as one listed on website above). 133kb filesize
"Parsed_db" which is a small portion/sample of the database (64,000+ accounts). 8850kb filesize
"Full_db" which is the entire database with shitloads of passwords (1.3 million accounts). A whooping 73,468kb of filesize (which is A LOT for simple text)!

Good luck!
NiX
Wiki Admin
Posts: 7770

Locomotive Pandamonium


Reply #9 on: December 13, 2010, 12:04:41 PM

Looks to me like they only grabbed those who had real obvious passwords like "password" and "qwerty" and "asdfgh" rather than being some uber elite hack.

They only released the shitty ones. They have something like 1.3 million accounts dumped from the DB.

Quote
Will repeat one last time: there are torrents out there with passwords.

Three folders:
"Dumb_passwords.txt" which are, as the file says, dumb passwords (same as one listed on website above). 133kb filesize
"Parsed_db" which is a small portion/sample of the database (64,000+ accounts). 8850kb filesize
"Full_db" which is the entire database with shitloads of passwords (1.3 million accounts). A whooping 73,468kb of filesize (which is A LOT for simple text)!

Want to check to see if you're in the huge dump?

Quote
Follow these steps:

1. http://pajhome.org.uk/crypt/md5/
2. Enter your email address under "Input", and click on "MD5". Copy the "Result".
3. http://www.google.com/fusiontables/D...?dsrcid=350662
4. Click on "Show Options" and change the filter to "MD5". Paste the copied "Result" and see if it shows up on search. If it does then your password has been compromised and sooner or later will be hacked if they feel like it.
Ingmar
Terracotta Army
Posts: 19280

Auto Assault Affectionado


Reply #10 on: December 13, 2010, 12:23:44 PM

I am soooooooooo not entering my email address in a form connected to any of these people.

The Transcendent One: AH... THE ROGUE CONSTRUCT.
Nordom: Sense of closure: imminent.
NiX
Wiki Admin
Posts: 7770

Locomotive Pandamonium


Reply #11 on: December 13, 2010, 12:53:03 PM

Google "MD5 Convert". Pick one you think is running on a secure line that can't be back traced. Tinfoil Hat
Thrawn
Terracotta Army
Posts: 3089


Reply #12 on: December 13, 2010, 01:05:11 PM

Wait what?  The passwords were just hidden with MD5?  I thought that was just a hashing algorythm and not really designed for use as encryption (and one that is known to not be secure at that).

"Sometimes I think the surest sign that intelligent life exists elsewhere in the Universe is that none of it has tried to contact us."
KallDrexx
Terracotta Army
Posts: 3510


Reply #13 on: December 13, 2010, 01:08:39 PM

Wait what?  The passwords were just hidden with MD5?  I thought that was just a hashing algorythm and not really designed for use as encryption (and one that is known to not be secure at that).

Passwords are usually hashed.  Encrypted data means that the data can be decrypted if the password (or whatever) is known, it's a 2 way street.

Hashes are one way, and the only way to determine the source string is to literally try hashing every combination of letters and find out which combination letters results in the same hash.  The MD5 vulnerablility only makes it so that after a certain number of characters the hashes have the potential to be the same for 2 different strings, but it's still unlikely. 
Tale
Terracotta Army
Posts: 8567

sıɥʇ ǝʞıן sʞןɐʇ


Reply #14 on: December 13, 2010, 01:09:43 PM

Wait what?  The passwords were just hidden with MD5?  I thought that was just a hashing algorythm and not really designed for use as encryption (and one that is known to not be secure at that).

Read the Forbes article I posted. Gawker appears to have no security guy and the boss used the same password for everything. One employee's password was myname1. And they were strutting around saying "Anonymous and 4chan lol, we're not scared of them, they'll never hack us".

Read about the extent of the Gawker hack and how poor their security is:

http://blogs.forbes.com/firewall/2010/12/13/the-lessons-of-gawkers-security-mess/
Thrawn
Terracotta Army
Posts: 3089


Reply #15 on: December 13, 2010, 01:19:22 PM

Yeah, I just quit being lazy and read the article.  I guess the passwords were encrypted with DES, which was cracked over ten years ago it looks like.  swamp poop

"Sometimes I think the surest sign that intelligent life exists elsewhere in the Universe is that none of it has tried to contact us."
Morfiend
Terracotta Army
Posts: 6009

wants a greif tittle


Reply #16 on: December 13, 2010, 02:22:14 PM

Anyone reading those sites deserves to have their shit hacked. lol at people who actually log in to any of those shit sites, especially the gossip ones.

I don't know about this. I read and enjoy Lifehacker. I find they publish some pretty good articles. Nothing mind blowing, but lightly informative.
Yegolev
Moderator
Posts: 24440

2/10 WOULD NOT INGEST


WWW
Reply #17 on: December 13, 2010, 02:37:48 PM


Why am I homeless?  Why do all you motherfuckers need homes is the real question.
They called it The Prayer, its answer was law
Mommy come back 'cause the water's all gone
NiX
Wiki Admin
Posts: 7770

Locomotive Pandamonium


Reply #18 on: December 13, 2010, 02:44:24 PM

Guess they dropped the CSV file. Probably because it was disgustingly large and getting far too many hits.
Samwise
Moderator
Posts: 19324

sentient yeast infection


WWW
Reply #19 on: December 13, 2010, 03:50:08 PM

I think your link got truncated when you copied it.  Unless that "..." is actually part of the URL.
Morfiend
Terracotta Army
Posts: 6009

wants a greif tittle


Reply #20 on: December 13, 2010, 11:39:16 PM

Not sure if this is real or phishing. Google thinks its real. I got this right after getting an email saying I tried to change my WoW password, which I didnt. I checked battle.net and didnt see anything about my password being reset.

Quote
Greetings!

We’ve recently been informed that several Gawker Media websites have been compromised. These websites include Gawker, Gizmodo, Kotaku, Lifehacker, Jezebel, io9, Jalopnik, Deadspin, and Fleshbot. To help minimize the effects of this compromise and help keep your Battle.net account safe and secure, we’ve reset your account password. To complete the password reset, please log into Battle.net Account Management (https://us.battle.net/account/management) and follow the provided instructions.

If you are a registered commenter for any of these sites and used your Battle.net email address to sign up with Gawker Media, we also recommend that you update your Battle.net address as soon as possible via Account Management. If you are unable to complete this step or the password reset on your own and believe your account may be compromised, please contact our customer support staff by using the Account Recovery form (https://us.battle.net/account/support/account-recovery.html) and be sure to check out our Account Security Awareness guide (http://us.battle.net/en/security/) for additional security tips and suggestions.

For more information about this situation, please visit Gawker Media’s official announcement (http://gawker.com/5713056/gawker-security-breach-were-here-to-help) or Lifehacker’s comprehensive FAQ (http://lifehacker.com/5712785/faq-compromised-commenting-accounts-on-gawker-media).


Regards,
Blizzard Entertainment
caladein
Terracotta Army
Posts: 3174


WWW
Reply #21 on: December 14, 2010, 12:14:58 AM

I got linked to http://www.didigetgawkered.com/ from Wonkette which split off from Gawker two years back if you don't want to use the above method.  Slate also has a similar tool up.  Still need to enter in a username or e-mail though.

As for the Blizzard e-mail, I haven't gotten anything like that at least and Gmail seems pretty good about picking out the fake Blizzard emails from the real ones.

"Point being, they can't make everyone happy, so I hope they pick me." -Ingmar
"OH MY GOD WE'RE SURROUNDED SEND FOR BACKUP DIG IN DEFENSIVE POSITIONS MAN YOUR NECKBEARDS" -tgr
Cadaverine
Terracotta Army
Posts: 1655


Reply #22 on: December 14, 2010, 11:33:43 AM

Not sure if this is real or phishing. Google thinks its real. I got this right after getting an email saying I tried to change my WoW password, which I didnt. I checked battle.net and didnt see anything about my password being reset.

I got the same thing last night.  I just deleted it, and I tried logging in to the WoW web site, and it was fine.

Every normal man must be tempted at times to spit on his hands, hoist the black flag, and begin to slit throats.
fuser
Terracotta Army
Posts: 1572


Reply #23 on: December 14, 2010, 01:31:01 PM

The fusion table for anyone catching up is: http://www.google.com/fusiontables/DataSource?dsrcid=350662
Morfiend
Terracotta Army
Posts: 6009

wants a greif tittle


Reply #24 on: December 14, 2010, 01:39:40 PM

Not sure if this is real or phishing. Google thinks its real. I got this right after getting an email saying I tried to change my WoW password, which I didnt. I checked battle.net and didnt see anything about my password being reset.

Quote
Greetings!

We’ve recently been informed that several Gawker Media websites have been compromised. These websites include Gawker, Gizmodo, Kotaku, Lifehacker, Jezebel, io9, Jalopnik, Deadspin, and Fleshbot. To help minimize the effects of this compromise and help keep your Battle.net account safe and secure, we’ve reset your account password. To complete the password reset, please log into Battle.net Account Management (https://us.battle.net/account/management) and follow the provided instructions.

If you are a registered commenter for any of these sites and used your Battle.net email address to sign up with Gawker Media, we also recommend that you update your Battle.net address as soon as possible via Account Management. If you are unable to complete this step or the password reset on your own and believe your account may be compromised, please contact our customer support staff by using the Account Recovery form (https://us.battle.net/account/support/account-recovery.html) and be sure to check out our Account Security Awareness guide (http://us.battle.net/en/security/) for additional security tips and suggestions.

For more information about this situation, please visit Gawker Media’s official announcement (http://gawker.com/5713056/gawker-security-breach-were-here-to-help) or Lifehacker’s comprehensive FAQ (http://lifehacker.com/5712785/faq-compromised-commenting-accounts-on-gawker-media).


Regards,
Blizzard Entertainment

Confirmed by Blizzard to be a scam.
ghost
The Dentist
Posts: 10619


Reply #25 on: December 14, 2010, 02:02:53 PM

I never click on any link in an email to change my password for anything.   Ohhhhh, I see.
Outlawedprod
Terracotta Army
Posts: 454


Reply #26 on: December 15, 2010, 06:46:41 AM

Confirmed by Blizzard to be a scam.

Wrong.
http://us.battle.net/wow/en/forum/topic/1536333940

Most likely they sent this just to people who have the same e-mail address registered with battle.net that was in the compromised gawker list.
Kitsune
Terracotta Army
Posts: 2406


Reply #27 on: December 15, 2010, 11:02:25 AM

My Yahoo mail account was bitching about repeated login failures when I checked it today, so someone's apparently trying to make a move with the stolen passwords.  Unluckily for them, my gawker password was longer than eight characters rendering what they stole useless, and I wasn't using that password for my email accounts in any event.

On a related note, here is a short paper I wrote on managing password security for my customers' reference.  It's common knowledge among the savvy, but may come in handy for some.
Tale
Terracotta Army
Posts: 8567

sıɥʇ ǝʞıן sʞןɐʇ


Reply #28 on: December 15, 2010, 12:28:02 PM

Confirmed by Blizzard to be a scam.

Wrong.
http://us.battle.net/wow/en/forum/topic/1536333940

Most likely they sent this just to people who have the same e-mail address registered with battle.net that was in the compromised gawker list.

A level 85 WoW player responds "Never heard of any of this". How could that be? :)
Pages: [1] Go Up Print 
f13.net  |  f13.net General Forums  |  General Discussion  |  Topic: Gawker Hacked - Change your password  
Jump to:  

Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC