Get a Pentest and security assessment of your IT network.

News

Ashley Madison Guilty Of Hard-Coded Creds, Weak Bot Detection

Avid Life Media hard-coded a variety of credentials into its source code, which may have helped enable the attack. ALM uses neither CAPTCHAs nor email verification to weed out bots during the account creation process, so individuals’ email addresses may have been used to create Ashley Madison profiles without their knowledge. Ashley Madison’s security team did encrypt users’ passwords, but some of the weakest passwords in the database could be cracked using bcrypt. The company did do right to encrypt the passwords.”]

Source: https://www.darkreading.com/attacks-breaches/ashley-madison-guilty-of-hard-coded-creds-weak-bot-detection

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin