Skip to main content

76,000 Mozilla Developers’ Email Addresses Compromised

A few days ago, members of Mozilla’s developer community were notified of the accidental leak of email addresses and encrypted passwords. This was a result of the failure of a “data ”sanitization process carried out by the company.
Mozilla is known worldwide for its Firefox Internet browser. The company coordinates the development of some open-source software projects via its Mozilla Developer Network.
From 23 June and for about 30 days, the company admits, data sanitization process had been failing. This caused the accidental disclosure of MDN email addresses of almost 76,000 users plus encrypted passwords of 4,000 users on a publicly accessible server. However, Mozilla said those passwords had been stored as salted hashes – an encryption process which rendered it computationally impossible to retrieve the original password in a readable format. The company also says that, by themselves, the passwords now can’t be used to authenticate with the MDN website.


Still, Mozilla added that some MDN users could have reused their original MDN passwords on other websites or authentication systems. Security experts confirmed that as soon as they learned of the leak, the database dump file was removed from the server immediately. In addition, the process generating the dump was disabled in order to prevent further disclosure. They also said that no malicious activity was detected on that server, but the experts admitted they can’t be 100% sure there wasn’t any such access.

In the meantime, the Mozilla Foundation recently named Chris Beard as the new permanent head of the corporation, after Brendan Eich resigned because of the controversy about his donations to a campaign against same sex marriage. At the time, the executive chairwoman of Mozilla Foundation said that they knew why people were hurt and angry, and they were right. She confirmed that Chris Beard was to stay on as Chief Executive Officer on a permanent basis, and pointed out that over the years he has led many of the company’s most innovative projects. Mozilla has relied on his judgment and advice for nearly ten years, and Beard is believed to have a clear vision of how to take Mozilla’s mission and turn it into industry-changing products and ideas.Perhaps, the new leader will have to start with apologies to all affected developers.

Comments

Popular posts from this blog

Here Are 7 Brilliant Cheat Sheets For Linux/Unix

There's nothing better than a cheatsheet when you are stuck and need a reference. So here bringing to you 7 brilliant free cheat sheets. 




1. Unix Tool Box: An incredibly exhaustive reference for all things Linux. This document is a collection of Unix/Linux/BSD commands and tasks which are useful for IT work or for advanced users.

2. One page Linux Manual: Great one page reference to the most popular Linux commands, it is a summary of useful Linux commands.

3. Linux Reference Card: One great reference published by FOSSwire.

4. Linux Command Line Cheat Sheet: This is an interestingly sorted and helpful cheat sheet by cheatography.

5. Linux Command Line Tips: This is a linux command line reference for common operations. Cleanly sorted and well described.

6. Treebeard’s Unix Cheat Sheet: A great reference that shows command comparisons with that of DOS. So if you are someone who was a DOS user and has switched to Linux, this is the best one too have!

7. Linux Shortcuts and Commands:…

Ten Important Rules Of Ethical Hacking

The world of ethical hacking too is bound by a set of rules and principles, here are 10 crucial ones!

Time and again we have been bringing you valuable resources on ethical hacking since we know and understand the nature of things as far as security goes. Ethical hacking is picking up steam each day with more and more organisations spending heftily to maintain the sanctity of their systems and data. As such, ethical hacking is a glorious career option in the current scheme of things.



1.Set your goals straight

To begin with, an ethical hacker must start thinking like the intruder. He must be able to identify the loopholes on the target access points or networks that are prone to attack, he must be aware of the repercussions of these loopholes and how the intruder can use it against the same. An ethical hacker then has to find out if anyone at the target notice the intruder's attempts to carry out his/her acts. Finding out and eliminating unauthorised wireless access points is always t…

Extracting Administrator Passwords Using LCP

Extracting Administrator Passwords Using LCP
Link Control Protocol (LCP) is part of the Point-to-Point (PPP) protocol In PPP communications, both the sending and receiving devices send out LCP packets to determine specific information required for data transmission.
■ Use an LCP tool ■ Crack administrator passwords
Tools Needed
■ A computer running Windows Server 2012 ■ A web browser with an Internet connection ■ Administrative privileges to run tools
■ You can also download the latest version of LCP from the link http: / www.lcpsoft.com/engl1sh/1ndex.htm
■ If you decide to download the latest version, then screenshots shown     might differ ■ Follow the wizard driven installation instructions ■ Run this tool in Windows Server 2012 ■ Administrative privileges to run tools ■ TCP/IP settings correctly configured and an accessible DNS server
Overview of LCP
LCP program mainly audits user account passwords and recovers them in Windows 2008 and 2003. General features of this protocol are password recovery, bru…