<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style id="owaParaStyle" type="text/css">
<!--
p
        {margin-top:0;
        margin-bottom:0}
-->
P {margin-top:0;margin-bottom:0;}</style>
</head>
<body ocsi="0" fpstyle="1">
<div style="direction: ltr; font-family: Verdana; color: rgb(0, 0, 0); font-size: 13px;">
<div style="">I've found, downloaded and analyzed the database.<br>
<br>
First, read this for the technical stuff that I'll not be going into: http://blogs.forbes.com/firewall/2010/12/13/the-lessons-of-gawkers-security-mess/<br>
<br>
Nutshell version: Gawker was arrogant and did not have the technical chops to back up their arrogance. They got smacked, hard, and because of that other people's data is at risk.<br>
<br>
The database dump contains a bunch of personal data about people that work at Gawker. That's vendetta stuff that only impacts them, so I won't be getting into it. The interesting stuff is in the database/ directory. They have the following files:<br>
<br>
dumb_passwords.txt - 2650 accounts with passwords like "password"<br>
parsed_db.txt - 188281 accounts with weak passwords that were decrypted.<br>
full_db.log - 1247893 accounts total.<br>
<br>
(For those that like math, look at the orders of magnitude there.)<br>
<br>
Now for the fun. There are 279 people on this mailing list. Of those people, seven of you are in listed in the Gawker dump... but two of you didn't store your passwords there. (Logging in with Facebook, hmmm?) The good news is that none of you showed up
on the dumb password list. The bad news is that three of you were using easily brute-forced passwords and your passwords are in the clear.<br>
<br>
I'll be contacting you three separately. :)<br>
</div>
<div><br>
<div style="font-family: Tahoma; font-size: 13px;">
<div style="font-family: Tahoma; font-size: 13px;">
<div style="font-family: Tahoma; font-size: 13px;">
<div style="font-family: Arial; font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;"><font size="2"><span style="font-size: 11pt;"><font size="2"><span style="font-size: 10pt;"><font size="3"><span style="font-weight: bold;">Josh More</span></font> | Senior Security Consultant - CISSP, GIAC-GSLC, GIAC-GCIH<br>
<span style="font-weight: bold;">Alliance Technologies</span> | <a href="http://www.alliancetechnologies.net" style="color: rgb(255, 0, 0);">
www.AllianceTechnologies.net</a><br>
400 Locust St., Suite 840 | Des Moines, IA 50309<br>
515.245.7701 | 888.387.5670 x7701<br>
</span></font></span></font><br>
Santa is Secure. Are you? <br>
<a href="http://www.alliancetechnologies.net/security/santa-2010">http://www.alliancetechnologies.net/security/santa-2010</a><br>
<br>
<font size="2"><span style="font-size: 11pt;"><font size="2"><span style="font-size: 10pt;">How are we doing? Let us know here:<br>
<a href="http://www.alliancetechnologies.net/forms/alliance-technologies-feedback-survey">http://www.alliancetechnologies.net/forms/alliance-technologies-feedback-survey</a><br>
</span></font></span></font>
<p class="MsoNormal"></p>
<div style="font-size: 13px;"></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div style="font-family: Times New Roman; color: rgb(0, 0, 0); font-size: 16px;">
<hr tabindex="-1">
<div style="direction: ltr;" id="divRpF50455"><font color="#000000" size="2" face="Tahoma"><b>From:</b> cialug-bounces@cialug.org [cialug-bounces@cialug.org] on behalf of Josh More<br>
<b>Sent:</b> Monday, December 13, 2010 10:57<br>
<b>To:</b> Central Iowa Linux Users Group<br>
<b>Subject:</b> Re: [Cialug] Change your password on gawker sites<br>
</font><br>
</div>
<div></div>
<div>
<div style="direction: ltr; font-family: Verdana; color: rgb(0, 0, 0); font-size: 13px;">
<div style="">You can check if your account was compromised here: <a href="http://www.google.com/fusiontables/DataSource?dsrcid=350662" target="_blank">
http://www.google.com/fusiontables/DataSource?dsrcid=350662</a><br>
<br>
Just do a search on the MD5 of your email address, instructions are in the right column of the spreadsheet.<br>
<br>
I'm still looking for the raw dump of the stolen data so I can analyze it.<br>
</div>
<div><br>
<div style="font-family: Tahoma; font-size: 13px;">
<div style="font-family: Tahoma; font-size: 13px;">
<div style="font-family: Tahoma; font-size: 13px;">
<div style="font-family: Arial; font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;">
<div style="font-size: 13px;"><font size="2"><span style="font-size: 11pt;"><font size="2"><span style="font-size: 10pt;"><font size="3"><span style="font-weight: bold;">Josh More</span></font> | Senior Security Consultant - CISSP, GIAC-GSLC, GIAC-GCIH<br>
<span style="font-weight: bold;">Alliance Technologies</span> | <a href="http://www.alliancetechnologies.net" style="color: rgb(255, 0, 0);" target="_blank">
www.AllianceTechnologies.net</a><br>
400 Locust St., Suite 840 | Des Moines, IA 50309<br>
515.245.7701 | 888.387.5670 x7701<br>
</span></font></span></font><br>
Santa is Secure. Are you? <br>
<a href="http://www.alliancetechnologies.net/security/santa-2010" target="_blank">http://www.alliancetechnologies.net/security/santa-2010</a><br>
<br>
<font size="2"><span style="font-size: 11pt;"><font size="2"><span style="font-size: 10pt;">How are we doing? Let us know here:<br>
<a href="http://www.alliancetechnologies.net/forms/alliance-technologies-feedback-survey" target="_blank">http://www.alliancetechnologies.net/forms/alliance-technologies-feedback-survey</a><br>
</span></font></span></font>
<p class="MsoNormal"></p>
<div style="font-size: 13px;"></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div style="font-family: Times New Roman; color: rgb(0, 0, 0); font-size: 16px;">
<hr tabindex="-1">
<div id="divRpF550695" style="direction: ltr;"><font color="#000000" size="2" face="Tahoma"><b>From:</b> cialug-bounces@cialug.org [cialug-bounces@cialug.org] on behalf of Matthew Nuzum [newz@bearfruit.org]<br>
<b>Sent:</b> Monday, December 13, 2010 09:13<br>
<b>To:</b> Central Iowa Linux Users Group<br>
<b>Subject:</b> [Cialug] Change your password on gawker sites<br>
</font><br>
</div>
<div></div>
<div>Hi, if you use lifehacker, gizmodo or one of the other gawker websites your password may have been compromised (along with 1.5M others)
<div><br>
</div>
<blockquote class="gmail_quote" style="margin: 0px 0px 0px 0.8ex; border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex;">
While initially denying the attack, Gawker has issued an apology to its users on all of its sites, urging them to change their passwords because of the attack. [1] If you have ever commented on any of the Gawker sites, we recommend that you go and change your
password. </blockquote>
<div><br>
</div>
<div><a href="http://www.digitaltrends.com/computing/gawker-hacked-1-5-million-accounts-compromised/" target="_blank">http://www.digitaltrends.com/computing/gawker-hacked-1-5-million-accounts-compromised/</a></div>
<div><br>
</div>
<div><br>
</div>
<div>[1] <a href="http://lifehacker.com/5712785/" target="_blank">http://lifehacker.com/5712785/</a><br clear="all">
<br>
</div>
<div><span class="Apple-style-span" style="font-family: 'Lucida Grande',Helvetica,Arial,sans-serif; font-size: 12px; line-height: 20px;">
<p style="margin: 0px 0px 1.5em; padding: 0px; border-width: 0px; outline-width: 0px; font-size: 12px; vertical-align: baseline; background-color: transparent;">
<strong style="margin: 0px; padding: 0px; border-width: 0px; outline-width: 0px; font-size: 12px; vertical-align: baseline; background-color: transparent;">1) How do I know if my password was hacked?</strong><br>
If you've registered an account on any Gawker Media web site (that includes Gawker, Gizmodo, Jalopnik, Jezebel, Kotaku, Lifehacker, Deadspin, io9, or Fleshbot), and you didn't log in using Facebook Connect, then it's best to assume that your username and password
were included among the leaked data.</p>
<p style="margin: 0px 0px 1.5em; padding: 0px; border-width: 0px; outline-width: 0px; font-size: 12px; vertical-align: baseline; background-color: transparent;">
Passwords in our database are encrypted (i.e., not stored in plain text), but they're still potentially vulnerable to hackers. You should immediately change the password on your account, and if you used that password on any other web site, <a href="http://lifehacker.com/5712785/#4" style="margin: 0px; padding: 0px; border-width: 0px; outline-width: 0px; font-size: 12px; vertical-align: baseline; background-color: transparent; text-decoration: none; color: rgb(120, 110, 41);" target="_blank">you
should change your passwords on all of those accounts</a> as well.</p>
<p style="margin: 0px 0px 1.5em; padding: 0px; border-width: 0px; outline-width: 0px; font-size: 12px; vertical-align: baseline; background-color: transparent;">
<strong style="margin: 0px; padding: 0px; border-width: 0px; outline-width: 0px; font-size: 12px; vertical-align: baseline; background-color: transparent;"><a name="2" style="margin: 0px; padding: 0px; border-width: 0px; outline-width: 0px; font-size: 12px; vertical-align: baseline; background-color: transparent; text-decoration: none; color: rgb(120, 110, 41);"></a>2)
What if I logged in using Facebook Connect? Was my password compromised?</strong><br>
No. We never stored passwords of users who logged in using Facebook Connect.</p>
<div><br>
</div>
</span>-- <br>
Matthew Nuzum<br>
newz2000 on freenode, skype, linkedin, <a href="http://identi.ca" target="_blank">
identi.ca</a> and twitter<br>
<br>
"An investment in knowledge pays the best interest." -Benjamin Franklin <br>
<br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</body>
</html>