Russian hackers exploited a hole in CNET's implementation of the Symfony PHP framework before pilfering a database containing usernames, emails, and encrypted passwords for more than a million registered users. The Russian hacker group that goes by w0rm recently breached CNET and pilfered a database containing usernames, emails, and encrypted passwords for more than a million registered users.On Saturday, @rev_priv8 tweeted “proof” of the hack.https//w0rm.in/cnet.com.tar.gz cnet hacked, here is src of www. pic.twitter.com/ggkaNF3VfE— w0rm (@rev_priv8) July 12, 2014 rev_priv8 for w0rm Janne Ahlberg, a product security professional and pentester who works at Microsoft, pointed out that the leaked source code package contained an offer to sell the CNET database for one bitcoin, which equaled $624.04 at the time of writing this post. CNET later said the group will not “distribute” its source code.A spokeswoman for CBS Interactive, which includes CNET, admitted that “a few servers were accessed. We identified the issue and resolved it a few days ago. We will continue to monitor.” When prodded for additional details, a spokesperson told SCMagazine, “We want to avoid sharing any information publicly that could motivate or invite any other issues. It’s shut down, it’s done and dusted, and there’s been no impact.” The hackers broke in by exploiting “a security hole [in] CNET’s implementation of the Symfony PHP framework.” The group said it targets insecure high-profile sites to raise security awareness. The group hacked BBC via FTP in 2013, as well as Adobe and Bank of America websites, allegedly for the same reason.“[W]e are driven to make the Internet a better and safer [place] rather than a desire to protect copyright,” w0rm told CNET. “I want to note that the experts responsible for bezopastnost [security] in cnet very good work but not without flaws.” TK Keanini, CTO of Lancope, told CIO that it is important to quickly learn the method and technique the hacking group used to compromise CNET due to the commonality of the infrastructure with other major websites.“Symfony is not only a popular framework used by many small and big corporations, but it is also the best platform to build Open-Source projects.” According to projects using Symfony, it used by Drupal, phpBB, and Piwik, to name a few.Yesterday, @rev_priv8 tweeted to CNET, “I have good protection system for u, ping me.”Although CNET did not advise registered users to change their password on the site, it might be wise. The passwords were encrypted, yet there is no additional information as to how they were protected or if they were salted and hashed.CNET said its registered users “might not be at risk,” before quoting White Hat Security’s Robert Hansen. “It definitely can feel like a slap in the face to an organization to be hacked,” Hansen said, “but in reality, most of the time in circumstances like this it’s actually a good thing. W0rm was careful not to give the full path to the actual exploit, and informed the general public that the compromise occurred.”“I guess we should feel grateful that the hackers don’t appear to be interested in exploiting the stolen information (and don’t appear to be serious about selling it onto others),” Graham Cluley told SCMagazineUK.com. “But I am disappointed that CNET hasn’t (so far at least) informed registered users of the security breach. Even if the passwords aren’t cracked, there is other personal information in there which could potentially be exploited by cyber criminals.” The potential for cybercrooks to get hold of a million users’ information “is why CNET should do the decent thing and reach out to affected users – warning them of the possibility of malicious emails and communications using some of the information that has been exposed,” Cluley added. Related content news Dow Jones watchlist of high-risk businesses, people found on unsecured database A Dow Jones watchlist of 2.4 million at-risk businesses, politicians, and individuals was left unprotected on public cloud server. By Ms. Smith Feb 28, 2019 4 mins Data Breach Hacking Security news Ransomware attacks hit Florida ISP, Australian cardiology group Ransomware attacks might be on the decline, but that doesn't mean we don't have new victims. A Florida ISP and an Australian cardiology group were hit recently. By Ms. Smith Feb 27, 2019 4 mins Ransomware Security news Bare-metal cloud servers vulnerable to Cloudborne flaw Researchers warn that firmware backdoors planted on bare-metal cloud servers could later be exploited to brick a different customer’s server, to steal their data, or for ransomware attacks. By Ms. Smith Feb 26, 2019 3 mins Cloud Computing Security news Meet the man-in-the-room attack: Hackers can invisibly eavesdrop on Bigscreen VR users Flaws in Bigscreen could allow 'invisible Peeping Tom' hackers to eavesdrop on Bigscreen VR users, to discreetly deliver malware payloads, to completely control victims' computers and even to start a worm infection spreading through VR By Ms. Smith Feb 21, 2019 4 mins Hacking Vulnerabilities Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe