<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lacisoft&#039;s &#187; hacked</title>
	<atom:link href="http://www.lacisoft.com/blog/tag/hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lacisoft.com/blog</link>
	<description>SELECT * FROM lacisoft</description>
	<lastBuildDate>Mon, 30 Jan 2012 17:42:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Typo3.org hacked &#8211; Why storing passwords in plain text is a stupid ideea</title>
		<link>http://www.lacisoft.com/blog/2008/11/14/typo3org-hacked-why-storing-passwords-in-plain-text-is-a-stupid-ideea/</link>
		<comments>http://www.lacisoft.com/blog/2008/11/14/typo3org-hacked-why-storing-passwords-in-plain-text-is-a-stupid-ideea/#comments</comments>
		<pubDate>Fri, 14 Nov 2008 13:14:24 +0000</pubDate>
		<dc:creator>lacisoft</dc:creator>
				<category><![CDATA[rampant stupidity]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[typo3]]></category>
		<category><![CDATA[typo3.org]]></category>

		<guid isPermaLink="false">http://www.lacisoft.com/blog/?p=59</guid>
		<description><![CDATA[I&#8217;ve just got an email from typo3.org (where i have an account) informing me that their site was hacked and the users/passwords were stolen. So i should change my passwords on other sites if they are there too. Here is a fragment from the email: &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- We have to inform you that an unauthorized person [...]
Related posts:<ol>
<li><a href='http://www.lacisoft.com/blog/2009/02/10/critical-security-issue-in-typo3-core-all-versions/' rel='bookmark' title='Critical security issue in Typo3 core &#8211; all versions'>Critical security issue in Typo3 core &#8211; all versions</a></li>
<li><a href='http://www.lacisoft.com/blog/2011/01/21/the-future-of-typo3-v4/' rel='bookmark' title='The future of TYPO3 v4'>The future of TYPO3 v4</a></li>
<li><a href='http://www.lacisoft.com/blog/2009/03/24/typo3-installation-and-upgrade-e-book/' rel='bookmark' title='TYPO3 Installation and Upgrade E-book'>TYPO3 Installation and Upgrade E-book</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve just got an email from typo3.org (where i have an account) informing me that their site was hacked and the users/passwords were stolen. So i should change my passwords on other sites if they are there too.</p>
<p>Here is a fragment from the email:</p>
<blockquote><p><em>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</em><em>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</em></p>
<p><em>We have to inform you that an unauthorized person has gained administrative<br />
access to the TYPO3.org website.</em></p>
<p><em>The offender had access to website user details including their passwords, and<br />
there have been reports of this data being used to access other websites.<br />
It also has to be expected that the data may have been disclosed to third<br />
parties.</em></p>
<p><em>Important!<br />
IF YOU HAVE USED THE SAME PASSWORD ON ANY OTHER SITE, PLEASE CHANGE IT<br />
IMMEDIATELY!</p>
<p></em><em>We have set up an FAQ page at </em><a href="http://typo3.org/about/faq/t3org-issue/" target="_blank"><em>http://typo3.org/about/faq/</em><em>t3org-issue/</em></a><em><br />
The page may be updated with new questions from time to time, so make sure to<br />
check back before replying to this mail.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</em><em>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</em></p></blockquote>
<p>How stupid should someone be to store passwords in plain text ? Because i must suppose that they were stored in plain text. Sincerely i expected more from the typo3 guys. No matter how secure you think your application is you must always store passwords encrypted with some algorithm. Because if someone gains access to the database (it could be a hacker, it could be a former employee and so on) it will have much less to gain from that database. </p>
<p>This way typo3.org compromised probably hundreds if not thousands of people&#8217;s accounts on other sites. Sure it would be ideal to have a unique password for each site but as practice shows many people use same password everywhere or at least in many places.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lacisoft.com%2Fblog%2F2008%2F11%2F14%2Ftypo3org-hacked-why-storing-passwords-in-plain-text-is-a-stupid-ideea%2F&amp;title=Typo3.org%20hacked%20%26%238211%3B%20Why%20storing%20passwords%20in%20plain%20text%20is%20a%20stupid%20ideea" id="wpa2a_2"><img src="http://www.lacisoft.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p><p>Related posts:<ol>
<li><a href='http://www.lacisoft.com/blog/2009/02/10/critical-security-issue-in-typo3-core-all-versions/' rel='bookmark' title='Critical security issue in Typo3 core &#8211; all versions'>Critical security issue in Typo3 core &#8211; all versions</a></li>
<li><a href='http://www.lacisoft.com/blog/2011/01/21/the-future-of-typo3-v4/' rel='bookmark' title='The future of TYPO3 v4'>The future of TYPO3 v4</a></li>
<li><a href='http://www.lacisoft.com/blog/2009/03/24/typo3-installation-and-upgrade-e-book/' rel='bookmark' title='TYPO3 Installation and Upgrade E-book'>TYPO3 Installation and Upgrade E-book</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.lacisoft.com/blog/2008/11/14/typo3org-hacked-why-storing-passwords-in-plain-text-is-a-stupid-ideea/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

