TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Gawker Website source, databases & passwords now on BitTorrent

365 pointsby tenaciousJkover 14 years ago

37 comments

alanhover 14 years ago
I think I am going to be checking the dump to ensure my password is not among it…<p>Remember, don’t use the same password across the Internet. Here’s why.<p><i>Edit:</i> It’s there, apparently as a DES hash. …<p><i>Update 2:</i> The first two characters are the hash. So if you use a tool like <a href="https://hash.online-convert.com/des-generator" rel="nofollow">https://hash.online-convert.com/des-generator</a> you are going to put your password in the “Text you want to convert…” box and the first two characters of your hashed password in as the “Salt (optional)”. Then you will see the “Calculated DES Hash” which will be the same as the hashed password from the torrent if you knew or guessed the password correctly.<p>E.g.<p>Your Lifehacker password is “hackern”, but in the torrent, it’s just “8h48GPxmwy.EA”. Just to show the torrent is legit, you go to the website I entered above, enter “hackern” and “8h” as the salt; it will spit back “8h48GPxmwy.EA”.<p><i>Update 3:</i> “OFFER HN”: The most paltry “Offer HN” ever — send me your username or email address and I’ll grep both files for you to see if your password and/or hash is in one of them. My email is contact-at-&#60;HN username&#62;ogan.com
评论 #1999515 未加载
评论 #1999373 未加载
评论 #1998965 未加载
评论 #1999227 未加载
评论 #1999329 未加载
评论 #1999923 未加载
评论 #1999555 未加载
评论 #1999074 未加载
评论 #1999403 未加载
评论 #2000571 未加载
kacyover 14 years ago
This is <i>serious</i>. I just checked out the torrent with the text file of the 200,000 cracked passwords. I searched for @me.com account and logged into someone's apple account. It was possible for me to order stuff via their account. I quickly emailed the guy to let him know to change his password. Gawker <i>needs</i> to take responsibility of this situation and email everyone in their database.
评论 #1999142 未加载
评论 #1999311 未加载
评论 #1999094 未加载
评论 #1999843 未加载
评论 #1999422 未加载
danilocamposover 14 years ago
My credentials were in the pile.<p>So, uh, how come I and everyone else affected don't have an email in our inboxes from Gawker right now, marked as urgent, explaining the situation?<p>Doesn't that seem like the right thing to do?
评论 #2000432 未加载
jbmover 14 years ago
Looks like it is quite easy to shut off ads on Gawker. They do a simple boolean check to see if you have a "noad" cookie set. Try entering this into the console.<p><pre><code> javascript:document.cookie='noad=true; expires=Thu, 2 Aug 2021 20:47:11 UTC; path=/'; </code></pre> This shuts everything off, except for one ad at the top.<p>(Put a bookmarklet for this if anyone who wants to try it out: <a href="http://bit.ly/exvive" rel="nofollow">http://bit.ly/exvive</a>)
Q6T46nT668w6i3mover 14 years ago
Has anyone checked if source/ contains the source for their proprietary CMS?<p>From Felix Salmon:<p><i>Most of the value of Gawker Media lies in Hungary—but how much value is there, really? To a large degree that depends on what Denton decides to do with his proprietary technology. Other blogging platforms are worth nine-figure sums—Tumblr just got a valuation of $135 million, while Automattic, the parent of WordPress, turned down a $200 million acquisition offer three years ago, when it was much smaller than it is today, and subsequently raised money at a valuation north of $150 million. I know a lot of people at big media companies who struggle with the limitations of WordPress, and who would pay good money to license an alternative web publishing technology, if it was robust and proven. Big companies are already licensing the NYT’s Press Engine mobile-publishing technology, and it’s rumored that at one point Denton was talking to Bonnie Fuller about licensing his technology to her nascent website, although that never happened.</i><p><a href="http://news.ycombinator.com/item?id=1998642" rel="nofollow">http://news.ycombinator.com/item?id=1998642</a>
评论 #1999632 未加载
评论 #1999397 未加载
评论 #1999395 未加载
wattyover 14 years ago
This is a huge breach yet users have to scroll down a full page on Gizmodo.com to find a small article about it.
评论 #1998843 未加载
评论 #2000449 未加载
paulitexover 14 years ago
I've download the torrent, convenient of them to give an email address with each cracked account.<p>I'm currently writing a little script that parses all the address and emails the owner a heads up. I gotta step out so I won't have it done for 2-3 hours and I thought I'd post here in case anyone else has that idea (don't want to flood the victims).
评论 #1999600 未加载
wipplerover 14 years ago
For anyone who is interested in more details, check out the readme file for how it actually went, atleast a rough sketch of it..<p><a href="http://pastebin.com/cpb7ndV8" rel="nofollow">http://pastebin.com/cpb7ndV8</a>
评论 #1999022 未加载
评论 #1999459 未加载
brandnewlowover 14 years ago
Random datapoint: My e-mail was one that got hit in this hack. 15 minutes ago my Twitter and Gmail both just locked me out. I was able to set new passwords via mobile verification, but that was pretty spooky and clearly someone is going after the people who got exposed here.
评论 #2004936 未加载
评论 #2000870 未加载
kmfrkover 14 years ago
Having seen the pastebin link, these guys use really, really poor password. Only alphanumeric - usually just one of the two - rarely with capitalization, and nothing else.
评论 #1999073 未加载
评论 #1998979 未加载
lotidesover 14 years ago
Can Gawker be held legally liable for maintaining poor security standards and incompetence leading to this? Can anybody cite related laws or cases?
评论 #2002604 未加载
sams99over 14 years ago
When will people learn to use bcrypt for their passwords, and on that topic, when will a "security expert" bless it <a href="http://stackoverflow.com/q/3722780/17174" rel="nofollow">http://stackoverflow.com/q/3722780/17174</a>
wizardishungryover 14 years ago
Does anyone have any information on changing all their account passwords at once? I don't use the same password for any sites, but unimportant sites like blogs, etc. I use fairly similar passwords on.
fendrakover 14 years ago
For a little background information on DES password hashing, check out this assignment from my Computer Security class at UT Austin:<p><a href="http://www.cs.utexas.edu/users/byoung/cs361/crack-assignment.html" rel="nofollow">http://www.cs.utexas.edu/users/byoung/cs361/crack-assignment...</a><p>It gives a little bit of background information on password hashing and salting, and on simple password cracking techniques.
beaumartinezover 14 years ago
TPB have removed the torrent.
quellhorstover 14 years ago
The torrent has been removed. Is there another place to download?
评论 #2001691 未加载
philfreoover 14 years ago
Seriously, use 1Password... it's great.
评论 #1999650 未加载
评论 #1999779 未加载
评论 #1999756 未加载
flexdover 14 years ago
I had no clue what gawker was until i saw this. Am i expected to
评论 #2000090 未加载
dataminerover 14 years ago
Its a good idea to use Keepass and Keyfox to generate different secure passwords for every site instead of using one weak password for all the sites.
ShabbyDooover 14 years ago
So, were these "passwords" stored as salted hashes?
评论 #1998820 未加载
评论 #1998783 未加载
评论 #1998766 未加载
jtagenover 14 years ago
I wonder if there's an option for an ISP to proactively secure these accounts. GMail has phone verification for backup, they could temporarily disable the account of anyone who has a matching password.<p>Odd, I'm sure I had a lifehacker comments account, but my username isn't listed. No complaints though.
liedraover 14 years ago
I have an io9 account (that's a Gawker site) but my email isn't showing up in a grep of the db dumps. Perhaps this is not the entire database after all? (I didn't use Facebook Connect.)<p>I must admit I'm a bit intrigued as to why mine's not there. Anyone else in this boat?
评论 #1999951 未加载
nhangenover 14 years ago
I'm in there, and I'm grateful to the HN community for showing me how to find out. This is rather alarming...I've passed it on to my newsletter subscribers, Twitter, Facebook, etc.<p>Kind of ironic really, considering the whole secrecy vs non-secrecy debate.
dacortover 14 years ago
Looks like somebody decided to spam the heck out of Twitter with those compromised passwords. <a href="http://twitter.com/#!/delbius/statuses/14235293116792833" rel="nofollow">http://twitter.com/#!/delbius/statuses/14235293116792833</a>
评论 #2000391 未加载
评论 #2000396 未加载
norovaover 14 years ago
I'm currently sending emails to the first 50,000 addresses listed in the database dump via SendGrid. I only have 50,000 credits left for this month, but at least that many will get notified.
评论 #1999554 未加载
bhrgunathaover 14 years ago
Does anyone have a list of sites that gawker owns - I have no idea which sites I need to potentially check.<p>EDIT: Nevermind - it seems that resetting your password at gawker.com resets for all of their sites.
redthrowawayover 14 years ago
This is what mailinator and, failing that, tenminutemail accounts are for. Why people sign up for random sites with their personal emails just to comment on articles is beyond me.
anigbrowlover 14 years ago
The passwords aren't very important, although I can see why that'd be an issue. But those internal chat logs are going to be a bit of a problem. For Nick Denton, that is.
enkoover 14 years ago
Damn, I'm on the list as well. This is the straw that broke the camel's back - I'm buying 1passwd, and converting to it wholesale.
ericfloover 14 years ago
Was this a Campfire hack, or did they happen to know a username/password combo and try Campfire first?
olalondeover 14 years ago
Anyone how they got access to their Campfire account? (That's where they found the server passwords)
评论 #1999263 未加载
jdbeast00over 14 years ago
does anyone know if their other sites db's were compromised aside from gawker.com?
评论 #1999048 未加载
arnover 14 years ago
any chance it's related to this?<p><a href="https://forum.bytemark.co.uk/comments.php?DiscussionID=2701" rel="nofollow">https://forum.bytemark.co.uk/comments.php?DiscussionID=2701</a>
评论 #1998837 未加载
评论 #1998838 未加载
truciousover 14 years ago
torrent not found..
Keyframeover 14 years ago
Early Christmas for spammers. What a disaster.
iphoneedbotover 14 years ago
Im curious, how come it only shows 65k email addresses, but everywhere Ive read reports email addresses totaling over a million
评论 #1999731 未加载
drivebyacct2over 14 years ago
Weird... One of my throwaway accounts appears with a name I know I've never used before. Then again, I had someone sign up for a Facebook account with that email address once too...
评论 #2001803 未加载