|
by Dan Driedelberg 05/19/2019, 8:42pm PDT |
|
 |
|
 |
|
"Ogusers.com -- a forum popular among people involved in hijacking online accounts and conducting SIM swapping attacks to seize control over victims' phone numbers -- has itself been hacked," reports security researcher Brian Krebs, "exposing the email addresses, hashed passwords, IP addresses and private messages for nearly 113,000 forum users."
On May 12, the administrator of OGusers explained an outage to forum members by saying a hard drive failure had erased several months' worth of private messages, forum posts and prestige points, and that he'd restored a backup from January 2019. Little did the administrators of OGusers know at the time, but that May 12 incident coincided with the theft of the forum's user database, and the wiping of forum hard drives. On May 16, the administrator of rival hacking community RaidForums announced he'd uploaded the OGusers database for anyone to download for free...
"The website owner has acknowledged data corruption but not a breach so I guess I'm the first to tell you the truth. According to his statement he didn't have any recent backups so I guess I will provide one on this thread lmfao."
Some users of the hijacking forum complained that their email addresses had started getting phishing emails -- and that the forum's owner had since altered the forum's functionality so user's couldn't delete their accounts.
"It's difficult not to admit feeling a bit of schadenfreude in response to this event..." writes Krebs, adding "federal and state law enforcement investigators going after SIM swappers are likely to have a field day with this database, and my guess is this leak will fuel even more arrests and charges for those involved."
-
..... SIM swapping. Huh. That's great for MFA. |
|
 |
|
 |
|
|
|
I hate a lot of implementations of MFA by Ice Cream Jonsey 04/28/2019, 8:54am PDT 
SMS isn't MFA and can be intercepted. It's just a webshit doing the laziest. NT by The Happiness Engine 04/29/2019, 3:50pm PDT 
Some people keep a burner phone with a secret number just for this. by Blackwater 05/01/2019, 6:48pm PDT 
MFA is a mess, continued by Ice Cream Jonsey 05/14/2019, 7:36am PDT 
Did you see this post on slashdot? by Dan Driedelberg 05/19/2019, 8:42pm PDT 
The saddest thing is that we actually have the tech to make 2FA work for real by blackwater 05/22/2019, 8:31am PDT 
Tell me more about this Yubikey. Sell me on it. NT by Jack Bauer 05/22/2019, 8:53pm PDT 
basically it is a physical thing you carry it around that unlocks stuff by Blackwater 05/22/2019, 10:14pm PDT 
My bank's awful "MFA" stuff by Ice Cream Jonsey 09/21/2019, 9:29am PDT 
In theory, the "spirit animal" stuff does make sense by blackwater 09/21/2019, 3:00pm PDT 
It kind of locks them into always having to display it though by - 09/21/2019, 4:01pm PDT 
Mine was a tiger! RAWRR!! NT by pinback 09/21/2019, 5:15pm PDT 
Lookin' good, MFA by Ice Cream Jonsey 03/15/2021, 2:18pm PDT 
Re: I hate a lot of implementations of MFA by Ice Cream Jonsey 11/20/2022, 12:18pm PST 
|
|