r3m1ck official site

The ordinary boy who like to programming java,programming python,developer a desktop application,mobile application,web designer

South Korean GOMTV.net streaming service hacked

Posted by admin On August - 16 - 2011 Views: 7,483


ToolBox
-

August 15th, 2011

Print this article

South Korean web users have been left reeling again just weeks after one of the biggest data breaches in the country’s history, after hackers attacked streaming service GOMTV.net and compromised details including names, email addresses and passwords.

A post on the site on Sunday revealed that attackers had breached the site early on Saturday morning local time, but fortunately GOMTV uses PayPal to process payments so no credit card details were stolen.

“We strongly encourage you to change your GOMTV.net password and if you have been using the same password for other web sites, we suggest changing the passwords for those sites as well,” noted the statement.

“As soon as we discovered the sign of intrusion we conducted a complete investigation into the incident and have also taken steps to enhance security and strengthen our network system in order to provide you with better protection of your personal information.”

Paul Ducklin, head of technology for Sophos Asia Pacific, welcomed GOMTV’s relatively quick notification of customers, but questioned the firm’s password retention policy.

“It sounds as though [parent company] Gretech was storing passwords in a directly recoverable form on its web servers. As we’ve said many times before on Naked Security, this is almost always unnecessary for online authentication,” he said in a blog post.

“You don’t need to save a user’s password permanently to be able to validate it later. Instead, you calculate and store a complex cryptographic hash of the password. If a user can subsequently provide a password which produces the same hash, you have satisifed yourself they know the password they chose originally. You need to have the password very briefly in memory, but you never need to store it.”

Ducklin also criticised the firm for placing a large button on the breach notification emails sent to customers designed to make it easier for them to change their password, as it could be exploited in the future by scammers.

“Fake warnings which urge users to click on links in the email they’ve just received are the hallmark of scammers and phishers,” he said.

“Avoid doing the same thing in your own alerts: this discourages users from entering confidential data on web pages they have reached via uncertain links embedded in emails.”

At the end of July, South Korea suffered potentially its largest ever data breach after an attack on the Nate online portal and Cyworld social network exposed up to 35 million users’ details.

15 Aug 2011

No tags for this post.

Facebook Comments

Leave a Reply

 

Hijacking firefox cookies with firesheep

When logging into a website you usually start by submitting your username and password. The server then checks to see if an account matching this information exists and if so, replies back to you with a “cookie” which is used by your browser for all subsequent Read the Rest…

The Most Amazing Villa In Mexico

The history of this villa has started in 1968 when a young Italian named Gian Franco Brignione saw these bays and lagoons from a small plane. Nowadays it is one of the most amazing villas in Costa Careyes, Mexico. Breathtaking views and the infinity pool Read the Rest…

Iran Prepares for Cyberwar

You know you’re a good target when someone hacks your website. Last year a website I was running for a conference on information warfare was hacked.  Rather, I should say, it was defaced. In my indelicate words, someone got onto the website and exchanged my Read the Rest…

Is LulzSec’s Leader at DefCon?

By Damon Poeter Post in pcmag Is Sabu at the DefCon security conference in Las Vegas? The LulzSec co-founder claimed to have been available Friday for a face-to-face meet up at the show in a series of tweets that turned into an exchange of taunts Read the Rest…

Modern Low House With Zen Garden And Green Roof

This modern family house is designed by architect Max Brunner. Everything is thought through to provide a comfortable indoor-outdoor living. Besides the house itself behind walls there are several courtyards and patio areas that are connected with different rooms. Floor to ceiling windows and slide Read the Rest…

Fans Box

  • Donate Me :)

  • Web Statistics