Results 1 to 1 of 1
-
21st Jun 2011, 02:24 AM #1OPMemberWebsite's:
ihide.infoDropbox bug allowed users into accounts without a password
Dropbox bug allowed users into accounts without a password
By Andrew Lyle
A serious Dropbox bug allowed anyone into another users account, without a correct password for hours yesterday.
According to Techcrunch, the security vulnerability was opened after a code update at 1:54 PM PST, allowing anybody to access someone's account with just their username credentials. The bug was later caught and fixed at 5:46 PM PST.
The security vulnerability was posted in a Pastebin account, leaving the information open to the public. Dropbox admits that there was an issue with their authentication mechanism, and that every users account was left vulnerable for close to four hours.
Dropbox did publish an apology and further explained that less than one percent of all Dropbox users logged in during that time. As a safety precaution, Dropbox ended all the sessions, logging everyone out.
Luckily for Dropbox and its user base, this information didn't fall into the wrong hands. However, a company that promotes security as one of its features (using AES-256) encryption and pushes code live without thoroughly testing and reviewing is concerning.
The email issued from Dropbox to its users:
Hi Dropboxers,
Yesterday we made a code update at 1:54pm Pacific time that introduced a bug affecting our authentication mechanism. We discovered this at 5:41pm and a fix was live at 5:46pm. A very small number of users (much less than 1 percent) logged in during that period, some of whom could have logged into an account without the correct password. As a precaution, we ended all logged in sessions.
We’re conducting a thorough investigation of related activity to understand whether any accounts were improperly accessed. If we identify any specific instances of unusual activity, we’ll immediately notify the account owner. If you’re concerned about any activity that has occurred in your account, you can contact us at security@dropbox.com.
This should never have happened. We are scrutinizing our controls and we will be implementing additional safeguards to prevent this from happening again.
-ArashShareShiz Reviewed by ShareShiz on . Dropbox bug allowed users into accounts without a password Dropbox bug allowed users into accounts without a password By Andrew Lyle A serious Dropbox bug allowed anyone into another users account, without a correct password for hours yesterday. According to Techcrunch, the security vulnerability was opened after a code update at 1:54 PM PST, allowing anybody to access someone's account with just their username credentials. The bug was later caught and fixed at 5:46 PM PST. The security vulnerability was posted in a Pastebin account, leaving Rating: 5KWWH has turned gay. I will not return until Phamous is demoted.
Sponsored Links
Thread Information
Users Browsing this Thread
There are currently 2 users browsing this thread. (0 members and 2 guests)
Similar Threads
-
Dropbox Users Emails Hacked - Confirmed
By Mr Happy in forum News & Current EventsReplies: 12Last Post: 1st Aug 2012, 12:13 PM -
Web-hosting service DreamHost warns users of password hack
By Bharat in forum News & Current EventsReplies: 0Last Post: 22nd Jan 2012, 06:24 AM -
[Other] RDP Accounts, OVH France Encoding Allowed Starts 30.00 USD Limited Slots
By intensecool in forum ArchiveReplies: 4Last Post: 16th Sep 2011, 02:24 PM -
[Other] RDP Accounts - OVH France (16CPUS,10GBPort ) - Encoding Allowed
By jessepure in forum ArchiveReplies: 56Last Post: 20th Oct 2010, 06:19 PM -
[Other] RDP Accounts ,, OVH France ,, Encoding Allowed
By ArDown in forum ArchiveReplies: 200Last Post: 14th Oct 2010, 03:33 AM
themaPoster - post to forums and...
Version 5.22 released. Open older version (or...