OpenSubtitles hacked, change password

The popular OpenSubtitles website, a site that provides free subtitles for movie lovers, revealed today that it was breached last year and paid a ransom to prevent the hacker from revealing the attack.

opensubtitles

The company today revealed the incident when a copy of the stolen files leaked leaked to the internet and was indexed by HaveIBeenPwned.

OpenSubtitles reported that the data of 6.783.158 users on its website was stolen. This data includes usernames and encrypted passwords, but which used the MD5 algorithm.

“The site was created in 2006 with minimal security knowledge, so passwords were stored with md5() without salt,” the site says in a suspension in the forum that describes the incident in detail.

This means that passwords could be decrypted. So those who have accounts should change their password immediately, and if you use the same password in other services you should do the same.

OpenSubtitles states that any information from payments is stored outside of its platform.

Analyzing the incident further, OpenSubtitles reported that the blackmail attempt took place last August. The reason for the breach was one of the administrators, who used a weak password.

In August 2021 we received a message in the Telegram from a hacker, who showed us that he could access the opensubtitles.org user table and download SQL.

He demanded a ransom in BTC for not revealing it to the public and promised to delete the data.

We agreed with difficulty, because the amount of money was high. He explained to us how he was able to access it and helped us fix the error. Technically, he was able to hack a SuperAdmin's password and gain access to a non- script, το οποίο ήταν διαθέσιμο μόνο για τους SuperAdmin. Αυτό το script του επέτρεψε να πραγματοποιήσει SQL and extract the data.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
OpenSubtitles, iguru

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).