funsec mailing list archives

[privacy] Hundreds Of Gmail, Yahoo, MSN Passwords Exposed By Entertainment Web S ite


From: "Fergie" <fergdawg () netzero net>
Date: Wed, 28 Mar 2007 03:00:42 GMT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Via InformationWeek.

[snip]

A Los Angeles publisher of online lifestyle and entertainment magazines has
inadvertently exposed the personal e-mail addresses and passwords for
hundreds of its subscribers, InformationWeek has learned.

The victims are all members of sites operated by Splash Magazines
Worldwide, which publishes local versions of its magazines under URLs like
NYCSplash.com and LASplash.com.

The list of e-mail addresses and passwords for members' Gmail, Hotmail,
Yahoo, and other accounts would turn up in the results of unrelated Google
searches Monday if those searches happened to contain at least two keywords
that matched the names of Splash members. InformationWeek confirmed that
the security hole was still open as of 4 p.m. Monday.

Splash founder Larry Davis said in an interview that he was not aware of
the security problem and did not know how it could have occurred. "We have
a Webmaster who is supposed to know all about security," said Davis.

[snip]

More:
http://www.informationweek.com/story/showArticle.jhtml?articleID=198700206

- - ferg

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.5.3 (Build 5003)

wj8DBQFGCdpVq1pz9mNUZTMRAvjLAKC8sk53E/CWyXss+IHpDTSg2ngXtQCgkoBe
1vmd1d9oVABE0BbVoUyIwiA=
=r5dq
-----END PGP SIGNATURE-----


--
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawg(at)netzero.net
 ferg's tech blog: http://fergdawg.blogspot.com/

_______________________________________________
privacy mailing list
privacy () whitestar linuxbox org
http://www.whitestar.linuxbox.org/mailman/listinfo/privacy


Current thread: