Live data from Hacker News

The unattributable “db8151dd” data breach

troyhunt.com

71–80 of 155 posts

Re: The unattributable “db8151dd” data breach

#71
Based on a large (over 50 results) domain search for a company I work for, the data I found was very old, circa 2014.

I know this because almost everyone in the domain search stopped working for the company on or after 2014. Everyone else has worked at the company since 2013 or earlier.

Re: The unattributable “db8151dd” data breach

#72
post #2

For the people that use unique per-merchant e-mail addresses (like someone+amazon@...), could you try some of those aliases on HaveIBeenPwned and see which ones come up in this breach? That might shed some light onto its origin.

For me, the HaveIBeenPwned domain search only lists one item in this breach: my LinkedIn@... email. Searching my inbox shows that the only emails sent to that address are from LinkedIn, so it probably came from a company I sent a job application (LinkedIn Easy Apply) to at some point.

Re: The unattributable “db8151dd” data breach

#73
post #2

For the people that use unique per-merchant e-mail addresses (like someone+amazon@...), could you try some of those aliases on HaveIBeenPwned and see which ones come up in this breach? That might shed some light onto its origin.

HaveIBeenPwned now has feature set to find e-mail addresses which were breached under a domain, there is normally no need to search for separate aliases if you own the e-mail domain. https://haveibeenpwned.com/DomainSearch

Unfortunately the email notifications don't tell you WHICH email addresses leaked.

Re: The unattributable “db8151dd” data breach

#74
post #2

For the people that use unique per-merchant e-mail addresses (like someone+amazon@...), could you try some of those aliases on HaveIBeenPwned and see which ones come up in this breach? That might shed some light onto its origin.

My gmail is on it, but not my burner-domain. So either the data is old (year or two), or they got my gmail from somewhere else. I'd be interested to see the whole dump to see my full record...

a year is not "old"

Re: The unattributable “db8151dd” data breach

#75

Based on a large (over 50 results) domain search for a company I work for, the data I found was very old, circa 2014. I know this because almost everyone in the domain search stopped working for the company on or after 2014. Everyone else has worked at the company since 2013 or earlier.

The email notification doesnt list the emails impacted. Do you need to rerun the full report to get the details?

Re: The unattributable “db8151dd” data breach

#76
post #38

I don't really get the utility of HIBP. The answer to the "have I been pawned?" question is, of course, yes, multiple times. I think about the only way to keep your email out of the hands of the bad guys is to not use it or give it to anyone ever, at which point you don't need an email address. What am I supposed to do whenever I'm involved in a new breach? Burn all my accounts and start again?

If you use a password manager to give you unique passwords per site, then these alerts allow you to only change the impacted site's passwords.

...though in a case like this it wouldn't help since we don't know the site.

Re: The unattributable “db8151dd” data breach

#77

Earlier quoted context omitted.

On the BambooHR issue, can you elaborate a bit more?

BambooHR is written in PHP and as it is widely known PHP allows incompetent programmers to create insecure websites. The majority of BambooHR pages are loaded by referencing a page ID, for example, you can access this URL [1] to render a form that allows you to send documents to arbitrary e-mail addresses, and this URL [2] allows you to edit your own profile. So far so good, if you are a competent PHP programmer (or…

I reviewed them when looking for a HR provider...thankfully they didn't offer everything I was looking for. But man, that's scary

Re: The unattributable “db8151dd” data breach

#78

Dataset for sale: [redacted] Similar data structure: https://stackblitz.com/edit/angular-soswe4?file=src%2Fapp%2F... Owner works for: https://covve.com Covve: This simple yet state-of-the-art app will revolutionise your business relations like you've never seen. Edit: Response: https://twitter.com/covve/status/1261287954967941120

Oh man, what is even going on with that raid forum.

Re: The unattributable “db8151dd” data breach

#79

Dataset for sale: [redacted] Similar data structure: https://stackblitz.com/edit/angular-soswe4?file=src%2Fapp%2F... Owner works for: https://covve.com Covve: This simple yet state-of-the-art app will revolutionise your business relations like you've never seen. Edit: Response: https://twitter.com/covve/status/1261287954967941120

The metadata in the breached records like "Imported from EverContacts" or similar supports the theory that it comes from a contacts app.

Re: The unattributable “db8151dd” data breach

#80

Dataset for sale: [redacted] Similar data structure: https://stackblitz.com/edit/angular-soswe4?file=src%2Fapp%2F... Owner works for: https://covve.com Covve: This simple yet state-of-the-art app will revolutionise your business relations like you've never seen. Edit: Response: https://twitter.com/covve/status/1261287954967941120

Oh man, what is even going on with that raid forum.

A quick glance suggests there's barely any skill in there and it's all bottom-feeders so you'd expect this to be an easy bust for law enforcement worldwide and yet they seem to be happily operating with total impunity for quite some time.
Post reply on HN