Warning: trigger_error(): It is not safe to rely on the system's timezone settings. You are *required* to use the date.timezone setting or the date_default_timezone_set() function. In case you used any of those methods and you are still getting this warning, you most likely misspelled the timezone identifier. We selected the timezone 'UTC' for now, but please set date.timezone to select your timezone. in /home/themoney/public_html/includes/database.mysql.inc on line 135

Warning: Table './themoney_2011new/watchdog' is marked as crashed and last (automatic?) repair failed query: INSERT INTO watchdog (uid, type, message, variables, severity, link, location, referer, hostname, timestamp) VALUES (0, 'php', '%message in %file on line %line.', 'a:4:{s:6:\"%error\";s:12:\"user warning\";s:8:\"%message\";s:176:\"Table './themoney_2011new/nodewords_custom' is marked as crashed and last (automatic?) repair failed\nquery: SELECT pid, path FROM nodewords_custom ORDER BY weight ASC\";s:5:\"%file\";s:71:\"/home/themoney/public_html/sites/all/modules/nodewords/nodewords.module\";s:5:\"%line\";i:1384;}', 3, '', 'http://themoneytimes.com/featured/20120712/yahoo-site-hacked-450k-passwords-posted-online-id-1701711906.html', '', '54.87.31.36', 1455011438) in /home/themoney/public_html/includes/database.mysql.inc on line 135

Warning: trigger_error(): It is not safe to rely on the system's timezone settings. You are *required* to use the date.timezone setting or the date_default_timezone_set() function. In case you used any of those methods and you are still getting this warning, you most likely misspelled the timezone identifier. We selected the timezone 'UTC' for now, but please set date.timezone to select your timezone. in /home/themoney/public_html/includes/database.mysql.inc on line 135

Warning: Table './themoney_2011new/watchdog' is marked as crashed and last (automatic?) repair failed query: INSERT INTO watchdog (uid, type, message, variables, severity, link, location, referer, hostname, timestamp) VALUES (0, 'php', '%message in %file on line %line.', 'a:4:{s:6:\"%error\";s:7:\"warning\";s:8:\"%message\";s:388:\"mktime(): It is not safe to rely on the system\'s timezone settings. You are *required* to use the date.timezone setting or the date_default_timezone_set() function. In case you used any of those methods and you are still getting this warning, you most likely misspelled the timezone identifier. We selected the timezone \'UTC\' for now, but please set date.timezone to select your timezone.\";s:5:\"%file\";s:93:\"/home/themoney/public_html/sites/all/modules/nodewords/nodewords_extra/nodewords_extra.module\";s:5:\"%line\";i:401;}', 3, '', 'http in /home/themoney/public_html/includes/database.mysql.inc on line 135

Warning: trigger_error(): It is not safe to rely on the system's timezone settings. You are *required* to use the date.timezone setting or the date_default_timezone_set() function. In case you used any of those methods and you are still getting this warning, you most likely misspelled the timezone identifier. We selected the timezone 'UTC' for now, but please set date.timezone to select your timezone. in /home/themoney/public_html/includes/database.mysql.inc on line 135

Warning: Table './themoney_2011new/watchdog' is marked as crashed and last (automatic?) repair failed query: INSERT INTO watchdog (uid, type, message, variables, severity, link, location, referer, hostname, timestamp) VALUES (0, 'php', '%message in %file on line %line.', 'a:4:{s:6:\"%error\";s:7:\"warning\";s:8:\"%message\";s:386:\"date(): It is not safe to rely on the system\'s timezone settings. You are *required* to use the date.timezone setting or the date_default_timezone_set() function. In case you used any of those methods and you are still getting this warning, you most likely misspelled the timezone identifier. We selected the timezone \'UTC\' for now, but please set date.timezone to select your timezone.\";s:5:\"%file\";s:93:\"/home/themoney/public_html/sites/all/modules/nodewords/nodewords_extra/nodewords_extra.module\";s:5:\"%line\";i:406;}', 3, '', 'http:/ in /home/themoney/public_html/includes/database.mysql.inc on line 135
Yahoo site hacked, 450K passwords posted online | The Money Times

Money Matters - Simplified

Yahoo site hacked, 450K passwords posted online

The hackers appear to have executed the breach through SQL injection, one of the most primitive and common methods of attack.

In the latest security breach, hackers infiltrated Internet search company Yahoo, accessing sensitive information from within the database.

A hacker group, known as D33Ds Company reportedly stole nearly half a million of its users’ email addresses and passwords and published them online.

The hacked content posted for public access includes plaintext credentials for 453,492 Yahoo accounts, more than 2,700 database table or column names, and 298 MySQL variables.

Security firm Trusted Sec, the first to report the breach stated, “The most alarming part to the entire story was the fact that the passwords were stored completely unencrypted and the full 400,000+ usernames and passwords are now public.”

The servers appear to have been compromised by the D33Ds Company with the intention of warning Yahoo for lax security.

SQL injection attack
The hackers appear to have executed the breach through SQL injection. The technique, one of the most primitive and common methods of attack, can successfully exploit vulnerable websites that “don't properly scrutinize text entered into search boxes and other user input fields."

The process can be used to trick the servers to submit huge amounts of sensitive information at the data base layer. The servers appear to have been compromised with the intention of warning Yahoo for lax security.

A brief note by the D33Ds Company accompanying the leaked file stated, “We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat. There have been many security holes exploited in webservers belonging to Yahoo! Inc. that have caused far greater damage than our disclosure. Please do not take them lightly. The subdomain and vulnerable parameters have not been posted to avoid further damage.”

Yahoo Voices compromised?
It is still ambiguous which service was infiltrated. The TrustedSec blog is reporting that details were retrieved from Yahoo Voice, the company’s service that pays freelance writers for content.

There are still others who believe the target was Yahoo Voices (with s) which is the company’s user-generated content service.

Given that many users use the same password for multiple services within one provider, its best to change the password.


Warning: trigger_error(): It is not safe to rely on the system's timezone settings. You are *required* to use the date.timezone setting or the date_default_timezone_set() function. In case you used any of those methods and you are still getting this warning, you most likely misspelled the timezone identifier. We selected the timezone 'UTC' for now, but please set date.timezone to select your timezone. in /home/themoney/public_html/includes/database.mysql.inc on line 135

Warning: Table './themoney_2011new/watchdog' is marked as crashed and last (automatic?) repair failed query: INSERT INTO watchdog (uid, type, message, variables, severity, link, location, referer, hostname, timestamp) VALUES (0, 'php', '%message in %file on line %line.', 'a:4:{s:6:\"%error\";s:12:\"user warning\";s:8:\"%message\";s:351:\"Table 'themoney_2011new.accesslog' doesn't exist\nquery: INSERT INTO accesslog (title, path, url, hostname, uid, sid, timer, timestamp) values('Yahoo site hacked, 450K passwords posted online', 'node/1701711906', '', '54.87.31.36', 0, '01ba6d972734b215dc0989c6513fcbb1', 213, 1455011438)\";s:5:\"%file\";s:63:\"/home/themoney/public_html/modules/statistics/statistics.module\";s:5:\"%line\";i:63;}', 3, '', 'http://themoneytimes.com/featur in /home/themoney/public_html/includes/database.mysql.inc on line 135