Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for FreePost Views: 47
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 2 Minutes
Clubhouse, the startup invitation-only chat app, is the latest social-media platform to see mammoth troves of user data collected and posted in underground forums. An SQL file containing the personal data of 1.3 million Clubhouse users has been posted in a hacker forum for free.
Clubhouse denies it was ‘breached’ and says the data is out there for anyone to grab.
Names, user IDs, photo URL, number of followers, Twitter and Instagram handles, dates that accounts were created and even the profile information of who invited them to the app are among the information contained in the database, according to CyberNews, giving threat actors key information which can be used against victims in phishing and other socially engineered scams.
For its part, Clubhouse said that its users’ data being public isn’t a bug, it’s just how the platform is built:
This is misleading and false. Clubhouse has not been breached or hacked. The data referred to is all public profile information from our app, which anyone can access via the app or our API. https://t.co/I1OfPyc0Bo
— Clubhouse (@joinClubhouse) April 11, 2021
See Also: Data from 500M LinkedIn Users Posted for Sale Online
The company isn’t supplying any other details and Clubhouse didn’t respond to Threatpost’s request for additional comment.
Clubhouse followers on Twitter were quick to note the statement points out a difference without any distinction to its exposed users.
“I fail to see what is false … ” user Benjamin Maynard responded to the Clubhouse statement. Leaky APIs Plague Social MediaClubhouse’s terms of service prohibit data scraping, yet its API, by its own admission, is sitting online with no protection against it.
“Clubhouse has conflicting user policies – being an invite-only platform and at the same time free-for-all user data,” Setu Kulkarni, vice president with WhiteHat Security said. “All it takes is one user to figure out the API for such large data egress of the millions of users on the platform.”
Kulkani added that these platforms need to shift to an API-first security strategy.
“Testing APIs in production is as if not more important than ever for not just vulnerabilities but also for business logic flaws that can result in unfettered access to user data,” he said.
https://media.threatpost.com/wp-content/uploads/sites/103/2021/04/12160922/leaked-database-image-300x115.png
The Clubhouse database. Click to enlarge. Source: CyberNews.
CyberNews researcher Mantas Sasnauskas analyzed the Clubhouse data and said the privacy bug is built into the platform itself.
“The way the Clubhouse app is built lets anyone with a token, or via an API, to query the entire body of public Clubhouse user profile information, and it seems that token does not expire,” Sasnauskas said.
The CyberNews team added that the SQL file posted in the hacker forum only has Clubhouse-related information and doesn’t include “sensitive data like credit-card details or legal documents.”
See Also: Offensive Security Tool: CVE Binary Tool by Intel Denying the ProblemIn the past two weeks, 533 million Facebook users’ data was leaked, LinkedIn saw scraping of 500 million people’s data and now Clubhouse has given up the information on another 1.3 million people.
And as Politico Europe’s N[...]
1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for FreePost Views: 47
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 2 Minutes
Clubhouse, the startup invitation-only chat app, is the latest social-media platform to see mammoth troves of user data collected and posted in underground forums. An SQL file containing the personal data of 1.3 million Clubhouse users has been posted in a hacker forum for free.
Clubhouse denies it was ‘breached’ and says the data is out there for anyone to grab.
Names, user IDs, photo URL, number of followers, Twitter and Instagram handles, dates that accounts were created and even the profile information of who invited them to the app are among the information contained in the database, according to CyberNews, giving threat actors key information which can be used against victims in phishing and other socially engineered scams.
For its part, Clubhouse said that its users’ data being public isn’t a bug, it’s just how the platform is built:
This is misleading and false. Clubhouse has not been breached or hacked. The data referred to is all public profile information from our app, which anyone can access via the app or our API. https://t.co/I1OfPyc0Bo
— Clubhouse (@joinClubhouse) April 11, 2021
See Also: Data from 500M LinkedIn Users Posted for Sale Online
The company isn’t supplying any other details and Clubhouse didn’t respond to Threatpost’s request for additional comment.
Clubhouse followers on Twitter were quick to note the statement points out a difference without any distinction to its exposed users.
“I fail to see what is false … ” user Benjamin Maynard responded to the Clubhouse statement. Leaky APIs Plague Social MediaClubhouse’s terms of service prohibit data scraping, yet its API, by its own admission, is sitting online with no protection against it.
“Clubhouse has conflicting user policies – being an invite-only platform and at the same time free-for-all user data,” Setu Kulkarni, vice president with WhiteHat Security said. “All it takes is one user to figure out the API for such large data egress of the millions of users on the platform.”
Kulkani added that these platforms need to shift to an API-first security strategy.
“Testing APIs in production is as if not more important than ever for not just vulnerabilities but also for business logic flaws that can result in unfettered access to user data,” he said.
https://media.threatpost.com/wp-content/uploads/sites/103/2021/04/12160922/leaked-database-image-300x115.png
The Clubhouse database. Click to enlarge. Source: CyberNews.
CyberNews researcher Mantas Sasnauskas analyzed the Clubhouse data and said the privacy bug is built into the platform itself.
“The way the Clubhouse app is built lets anyone with a token, or via an API, to query the entire body of public Clubhouse user profile information, and it seems that token does not expire,” Sasnauskas said.
The CyberNews team added that the SQL file posted in the hacker forum only has Clubhouse-related information and doesn’t include “sensitive data like credit-card details or legal documents.”
See Also: Offensive Security Tool: CVE Binary Tool by Intel Denying the ProblemIn the past two weeks, 533 million Facebook users’ data was leaked, LinkedIn saw scraping of 500 million people’s data and now Clubhouse has given up the information on another 1.3 million people.
And as Politico Europe’s N[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for FreePost Views:…
icholas Vinocur pointed out, they’ve all followed an eerily similar disclosure playbook: deny it ever happened.
In past ten days:
533 million people’s data leaked at Facebook.
500 million people’s data leaked at LinkedIn.
1.3 million people’s data leaked at Clubhouse.
All deny the data was leaked or there was a problem of any sort.
— Nicholas Vinocur (@NicholasVinocur) April 12, 2021
Facebook was similarly vulnerable through their API, which Michael Isbitski from Salt Security told Threatpost is becoming more common.
“Content scraping is a common attack pattern,” Isbitski said in the wake of the Facebook leak. “Organizations often build or integrate APIs, without fully considering the abuse cases of the APIs.”
LinkedIn also out a statement in the wake of its incident, explaining the platform wasn’t technically “breached,” but that the information was public and scraped from the LinkedIn site.
To view the LinkedIn user data file in the hacker forum, it costs $2 worth of forum credits. The full database was up for auction in the four-figures range.
“We have investigated an alleged set of LinkedIn data that has been posted for sale and have determined that it is actually an aggregation of data from a number of websites and companies” that includes “publicly viewable member-profile data that appears to have been scraped from LinkedIn,” the company said in a statement. “This was not a LinkedIn data breach, and no private member account data from LinkedIn was included in what we’ve been able to review.” See Also: Hacking Stories: When two young hackers played war games with PentagonData Scraping Fallout“I don’t expect that this will be the last of these sort of scraping incidents,” Isbitski predicted. “APIs are regularly the vehicle for functionality and data. Social media companies inherently design their platforms to be consumable, powering much of it with APIs. Attackers know this, and they continue to target APIs in scraping attacks, repurposing publicly available data for malicious purposes”
Users of all three of these social media platforms should be aware they could be targeted by email phishing campaigns, so strong passwords and multi-factor authentication are important. CyberNews offers a personal data leak checker to help users figure out if their data was compromised. Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/linkedin-90x90.png Data from 500M LinkedIn Users Posted for Sale Online1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/cisco-patch-90x90.png Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/google-play-90x90.jpg Fake Netflix App on Google Play Spreads Malware Via WhatsApp5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/vmware-patch-90x90.jpg Critical Cloud Bug in VMWare Carbon Black Allows Takeover6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/eggs-chickens-e1617650984482-90x90.jpg LinkedIn Spear-Phishing Campaign Targets Job Hunters1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/pf9bzNs3hHRgAcgDQTPPa3-1200-80-90x90.jpg Facebook data on 533 million users posted online1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/NAS-Bug-90x90.jpg Legacy QNAP NAS Devices Vulnerable to Zero-Day Attack2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/iphone-privacy-90x90.jpg Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting Out2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Monero-Mining-90x90.png Malicious Docker Cryptomining Images Rack Up 20M Downloads2 weeks ago
* https://www.blackhatet[...]
In past ten days:
533 million people’s data leaked at Facebook.
500 million people’s data leaked at LinkedIn.
1.3 million people’s data leaked at Clubhouse.
All deny the data was leaked or there was a problem of any sort.
— Nicholas Vinocur (@NicholasVinocur) April 12, 2021
Facebook was similarly vulnerable through their API, which Michael Isbitski from Salt Security told Threatpost is becoming more common.
“Content scraping is a common attack pattern,” Isbitski said in the wake of the Facebook leak. “Organizations often build or integrate APIs, without fully considering the abuse cases of the APIs.”
LinkedIn also out a statement in the wake of its incident, explaining the platform wasn’t technically “breached,” but that the information was public and scraped from the LinkedIn site.
To view the LinkedIn user data file in the hacker forum, it costs $2 worth of forum credits. The full database was up for auction in the four-figures range.
“We have investigated an alleged set of LinkedIn data that has been posted for sale and have determined that it is actually an aggregation of data from a number of websites and companies” that includes “publicly viewable member-profile data that appears to have been scraped from LinkedIn,” the company said in a statement. “This was not a LinkedIn data breach, and no private member account data from LinkedIn was included in what we’ve been able to review.” See Also: Hacking Stories: When two young hackers played war games with PentagonData Scraping Fallout“I don’t expect that this will be the last of these sort of scraping incidents,” Isbitski predicted. “APIs are regularly the vehicle for functionality and data. Social media companies inherently design their platforms to be consumable, powering much of it with APIs. Attackers know this, and they continue to target APIs in scraping attacks, repurposing publicly available data for malicious purposes”
Users of all three of these social media platforms should be aware they could be targeted by email phishing campaigns, so strong passwords and multi-factor authentication are important. CyberNews offers a personal data leak checker to help users figure out if their data was compromised. Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/linkedin-90x90.png Data from 500M LinkedIn Users Posted for Sale Online1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/cisco-patch-90x90.png Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/google-play-90x90.jpg Fake Netflix App on Google Play Spreads Malware Via WhatsApp5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/vmware-patch-90x90.jpg Critical Cloud Bug in VMWare Carbon Black Allows Takeover6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/eggs-chickens-e1617650984482-90x90.jpg LinkedIn Spear-Phishing Campaign Targets Job Hunters1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/pf9bzNs3hHRgAcgDQTPPa3-1200-80-90x90.jpg Facebook data on 533 million users posted online1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/NAS-Bug-90x90.jpg Legacy QNAP NAS Devices Vulnerable to Zero-Day Attack2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/iphone-privacy-90x90.jpg Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting Out2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Monero-Mining-90x90.png Malicious Docker Cryptomining Images Rack Up 20M Downloads2 weeks ago
* https://www.blackhatet[...]
Hacking Articles Tips Tricks Videos Tutorials
icholas Vinocur pointed out, they’ve all followed an eerily similar disclosure playbook: deny it ever happened. In past ten days: 533 million people’s data leaked at Facebook. 500 million people’s data leaked at LinkedIn. 1.3 million people’s data leaked…
hicalhacking.com/wp-content/uploads/2021/03/phph-90x90.jpg PHP Infiltrated with Backdoor Malware2 weeks ago
The post 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free first appeared on Black Hat Ethical Hacking.
The post 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
BlueBorne exploits - couple of BILLION vunreablle devices!
Hi,
I recently stumbled upon the BlueBorne exploit family. It consists of 8 vonrebilities on all sorts of OS. https://www.youtube.com/watch?v=LLNtZKpL0P8 https://www.youtube.com/watch?v=WWQTlogqF1I . If I manage to learn this I will be ready to have some fun hacking some IoT I have laying around ;) I just don't understand it all that well. I know there is the script that you have to run when you know the Mac address of the victim, but where can I download it and how excactly do I use it? Heck, is even using premade scripts safe?!
Cheers!
submitted by /u/PaintballAlex
[link] [comments]
BlueBorne exploits - couple of BILLION vunreablle devices!
Hi,
I recently stumbled upon the BlueBorne exploit family. It consists of 8 vonrebilities on all sorts of OS. https://www.youtube.com/watch?v=LLNtZKpL0P8 https://www.youtube.com/watch?v=WWQTlogqF1I . If I manage to learn this I will be ready to have some fun hacking some IoT I have laying around ;) I just don't understand it all that well. I know there is the script that you have to run when you know the Mac address of the victim, but where can I download it and how excactly do I use it? Heck, is even using premade scripts safe?!
Cheers!
submitted by /u/PaintballAlex
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
THE COOL LOOK
https://cdn-images-1.medium.com/max/1355/1*XIRhVj0Rtck6hQrNvgf7Cw.jpeg
This thing in the picture actually looks cool and it makes the interface looks like hacking… But, don’t get fooled so easily. It’s just a…
Continue reading on Medium »
THE COOL LOOK
https://cdn-images-1.medium.com/max/1355/1*XIRhVj0Rtck6hQrNvgf7Cw.jpeg
This thing in the picture actually looks cool and it makes the interface looks like hacking… But, don’t get fooled so easily. It’s just a…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Attacco informatico a Facebook e LinkedIn, pubblici i dati di milioni di utenti: I nostri dati…
https://cdn-images-1.medium.com/max/1600/1*r109wRDijzj0DCG0ramqsw.jpeg
Un utente ha pubblicato su un forum di hacking i dati di centinaia di milioni di utenti di Facebook, circa 533 milioni provenienti da…
Continue reading on BV TECH Group »
Attacco informatico a Facebook e LinkedIn, pubblici i dati di milioni di utenti: I nostri dati…
https://cdn-images-1.medium.com/max/1600/1*r109wRDijzj0DCG0ramqsw.jpeg
Un utente ha pubblicato su un forum di hacking i dati di centinaia di milioni di utenti di Facebook, circa 533 milioni provenienti da…
Continue reading on BV TECH Group »
Lazy XSS in the wild
A simple, yet common vulnerability that I stumbled across on tens of websitesContinue reading on Medium »
Read more...
A simple, yet common vulnerability that I stumbled across on tens of websitesContinue reading on Medium »
Read more...
A simple, yet common vulnerability that I stumbled across on tens of websitesContinue reading on Medium » (https://ivanff123.medium.com/lazy-xss-in-the-wild-9a402c43399b?source=rss------bug_bounty-5)
Anatomy of learning new things and keeping yourself updated in hacking
Hi homies, I hope you all are safe and doing your stuff constantly. Summer is up and we are increasing our speed:) I have so many plans to…Continue reading on InfoSec Write-ups »
Read more...
Hi homies, I hope you all are safe and doing your stuff constantly. Summer is up and we are increasing our speed:) I have so many plans to…Continue reading on InfoSec Write-ups »
Read more...
Anatomy of learning new things and keeping yourself updated in hacking
https://infosecwriteups.com/anatomy-of-learning-new-things-and-keeping-yourself-updated-in-hacking-40541ec9060b?source=rss------bug_bounty-5
https://infosecwriteups.com/anatomy-of-learning-new-things-and-keeping-yourself-updated-in-hacking-40541ec9060b?source=rss------bug_bounty-5