Get a Pentest and security assessment of your IT network.

News

Ashley Madison Guilty Of Hard-Coded Creds, Weak Bot Detection

Avid Life Media hard-coded a variety of credentials into its source code, which may have helped enable the attack. ALM uses neither CAPTCHAs nor email verification to weed out bots during the account creation process, so individuals’ email addresses may have been used to create Ashley Madison profiles without their knowledge. Ashley Madison’s security team did encrypt users’ passwords, but some of the weakest passwords in the database could be cracked using bcrypt. The company did do right to encrypt the passwords.”]

Source: https://www.darkreading.com/attacks-breaches/ashley-madison-guilty-of-hard-coded-creds-weak-bot-detection

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

RasGas, The Second Victim!

News

Technical analysis of the Locker virus on mobile phones