Jump to content

Hostinger (Major Web Host) Breached

Quote

The breach is said to have happened on Thursday. The company said in a blog post it received an alert that one of its servers was improperly accessed. Using an access token found on the server, which can give access to systems without needing a username or a password, the hacker gained further access to the company’s systems, including an API database containing customer usernames, email addresses, and scrambled passwords. It’s not known which kind of hashing algorithm was used. Depending on the algorithm used, an attacker may be able to unscramble user passwords.

 

Source: https://techcrunch.com/2019/08/25/web-host-hostinger-data-breach/

 

This ain't good.

Link to comment
https://linustechtips.com/topic/1097871-hostinger-major-web-host-breached/
Share on other sites

Link to post
Share on other sites

On 8/25/2019 at 12:49 PM, Car712 said:

Interesting, I had an account with them .. uh.. 6 years ago ?

Didin't get an email & idk if that's good or bad >.>

though I don't remember using that password anywhere anyway xD 

Edit : It took 4 days for them to notify me..

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to post
Share on other sites

24 minutes ago, givingtnt said:

Interesting, I had an account with them .. uh.. 6 years ago ?

Didin't get an email & idk if that's good or bad >.>

Yeah, I actually had a shared hosting plan (paid) with them a few years ago, got the email at about 9 AM (CST) this morning.

 

For some reason they don't note in their blog post that Home Addresses, and Phone Numbers were also leaked, but they mentioned it in the email (notice the comma after "email" in my squared area):

V6O1R5n_d.jpg?maxwidth=640&shape=thumb&f

 

Link to post
Share on other sites

1 minute ago, Car712 said:

Yeah, I actually had a shared hosting plan with them a few years ago, got the email at about 9 AM (CST) this morning.

 

For some reason they don't note in their blog post that Home Addresses, and Phone Numbers were also leaked, but they mentioned it in the email (notice the comma after 'email' in my squared area:

 

Interesting. I had the free hosting plan they used to offer (idk if they still do ?)

Been a while, & my thing has been down for years xD 

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to post
Share on other sites

10 minutes ago, Car712 said:

Might be able to unscramble.... lol It isn't a matter of if, but when. Some passwords might take longer than others but I would expect they have already started recovering passwords. Just another case of poor security practices.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×