Live data from Hacker News

LinkedIn password leak

usblog.kaspersky.com

1–10 of 218 posts

Re: LinkedIn password leak

#2
My theory is that this data leaked via custhelp.com, the filename of the data dump I have (linkedin.cfg) seems to support that.

This would also explain linkedins initial "confusion" regarding the hack.

Re: LinkedIn password leak

#3
Considering the amount of "growth hacking" LinkedIn use (used?) to so, sending too many emails to too many people this breach can be much more dangerous than usual.

People raises eyebrows when they get phishing emails but when it comes purposely from LinkedIn and vouched for by your social and professional circle it could get much more credible and easy to fall.

Re: LinkedIn password leak

#5
post #2

My theory is that this data leaked via custhelp.com, the filename of the data dump I have (linkedin.cfg) seems to support that. This would also explain linkedins initial "confusion" regarding the hack.

Could you elaborate? Also, when you say '"confusion"', do you mean it was feigned?

Re: LinkedIn password leak

#7
post #5
post #2

My theory is that this data leaked via custhelp.com, the filename of the data dump I have (linkedin.cfg) seems to support that. This would also explain linkedins initial "confusion" regarding the hack.

Could you elaborate? Also, when you say '"confusion"' , do you mean it was feigned?

Linkedins support site URLs (hosted by custhelp.com) used to look something like this http://linkedin.custhelp.com/cgi-bin/*linkedin.cfg*/php/endu...

I know custhelp used to be particularly insecure right around when this hack happened, as I myself discovered several vulnerabilities back then.

>Also, when you say '"confusion"', do you mean it was feigned?

Partly. From what I recall it took them quite a while to own up to this very easily verifiable hack, which could very well have been because they couldn't figure out why it happened because it didn't actually happen on their systems.

Re: LinkedIn password leak

#9
post #7
post #5

Earlier quoted context omitted.

Could you elaborate? Also, when you say '"confusion"' , do you mean it was feigned?

Linkedins support site URLs (hosted by custhelp.com) used to look something like this http://linkedin.custhelp.com/cgi-bin/*linkedin.cfg*/php/endu... I know custhelp used to be particularly insecure right around when this hack happened, as I myself discovered several vulnerabilities back then. >Also, when you say '"confusion"', do you mean it was feigned? Partly. From what I recall it took them quite a while to own u…

Wow, just looking at that URL is cause for concern.

Re: LinkedIn password leak

#10
post #7
post #5

Earlier quoted context omitted.

Could you elaborate? Also, when you say '"confusion"' , do you mean it was feigned?

Linkedins support site URLs (hosted by custhelp.com) used to look something like this http://linkedin.custhelp.com/cgi-bin/*linkedin.cfg*/php/endu... I know custhelp used to be particularly insecure right around when this hack happened, as I myself discovered several vulnerabilities back then. >Also, when you say '"confusion"', do you mean it was feigned? Partly. From what I recall it took them quite a while to own u…

Ah...I assumed that a leak happening via third-party would be an excuse for a company to be legit confused at first and then breathe a sigh of relief because that means they can blame someone else in the press release. Though I guess that's tricky when people start asking about why their data is being given in bulk to a third party in the first place...
Post reply on HN