Unknown hackers disclosed to the editorial team SecNews, the fact of the leak of 32,000 accounts from websites bourdela.comand adultforum.gr.The above websites are websites “special content” (for adults), with a very large number of users.It is worth mentioning that the websites are among the 350 most visited websites in Greece. This does not seem to have stopped the attackers, who managed to extract almost all the elements of the database.The unknown individuals contacted the editorial team of SecNews, taking measures to hide their details and provided evidence that proves beyond any doubt that the websites bourdela.com and adultforum.gr were targeted online. The hackers appear to have stolen information and data of 32,000 users. The information that the unknown individuals have at their disposal and made available to SecNews clearly shows: a) the username and encrypted password of each user (including administrators) b) the IP address of the user's access origin c) the registered email addresses. The attackers have hidden database information such as the full IP address and email so that they cannot be used maliciously by other hackers and innocent people can be targeted. The information that they have at their disposal was obtained, according to what they state in their message 3 days ago from the websites bourdela.com and adultforum.grOur assessment is that the data was obtained through a weakness in the website (possibly SQL Injection) which allowed hackers to obtain parts of the database. The administrators of the two websites, They do NOT seem to have realized the attack until now while there is no information about their members. It is worth noting that a rough analysis of the part of the database that was made public identified accesses from well-known public services, organizations, companies, but even from subsidiaries of Greek banks!! The website bourdela.com had been set up under investigation by Greek authorities in 2008a> with a lightning operation and arrest of the administrators. According to what the website says (we have not confirmed this), in 2013 the former administrator was discharged of all charges after multiple court adjournments.See also: Exclusive: Windows XP SP4 Unofficial FinalAccording to journalistic information brought to SecNews' attention by the attackers and we convey it with all reservations, There will soon be additional leaks of registered users from other websites that have extracted data. In addition, as they report, they have at their disposal discussions of members of the website as well as other personal information.Because according to the announced data, we estimate that personal data of users has been made available to third parties, we call on:
Organizations, companies, services and bodies to restrict access to the website through the proxy servers/content filters they have in place until it is checked by the competent administrators and there is an official announcement on the details of the attack.
Users who have accounts on the websites in question, adultforum.gr and bourdela.com, should change their passwords IMMEDIATELY. If the password is also used on other services (e.g. e-mail, social networks), change it IMMEDIATELY as well.
Website administrators should immediately request a password change (enforce password change) and analyze the relevant logs for details of the attack, in order to inform their members.
It has not been clarified by the perpetrators so far whether it was the entire base or part of it that they were able to intercept. The file uploaded to the anonymous drop-off point is 6MB.The full list of leaked users is available at this link. Check if your username is in the list above and proceed to change your password immediately. SecNews made the above update (despite the specific content of the website that was targeted) ldue to the increased number of members and unsuspecting users whose information was exposed.SecNews provided the above information (despite the specific content of the website that was targeted) ldue to the increased number of members and unsuspecting users whose information was exposed.SecNews thanks the unknown informant(s) for the valid and detailed information regarding the attack.