Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Fantasy Site Hack Exposes Data on 650,000 Users

Users of Second Life site forced to change passwords after zero-day exploit hits Web server

A hack on a popular Web fantasy site may have exposed the personal data of some 650,000 players, site operators revealed late last week.

Second Life, a virtual world in which players can live out another existence, was hit by a "zero-day exploit" last week, and a database containing players' names, addresses, passwords, and payment information was compromised, according to Linden Lab, which operates the site.

Systems administrators for Second Life voided all of the participants' passwords, forcing users to change to new passwords immediately. Users will have to answer a security question in order to get a new password.

Linden Lab was not specific about the details of the attack, and company officials did not reply to queries for this article. However, in messages to its customers, the company said the exploit was perpetrated on its Web server, via vulnerabilities in "third-party Web software."

So far, Linden Lab has been able only to determine the "aggregate size of the data that was downloaded through the intrusion," which appears to have been substantial. The company said it could not tell whether individual records were compromised, or which ones, which is why it decided to simply void all the passwords in the system and ask legitimate users to renew.

The database includes Second Life account names, real-life names, and contact information in unencrypted form, Linden Lab said. Account passwords and payment information (such as credit card numbers and PayPal transaction IDs) were also in the database but were encrypted via an MD-5 hash algorithm and "salt," which inserts additional data into the encryption pattern to make it harder to crack, the company said. A separate database that contained unencrypted credit card information was not compromised, according to Linden Lab.

"The compromised system was rebuilt and made more secure," Linden Lab said in its blog. The company plans to announce additional security improvements in the near future.

Second Life users, who log onto the site to buy virtual land, build virtual homes and try all sorts of pastimes they would never try in the real world, were frustrated by the intrusion.

"I've heard a number of people say it was bound to happen sooner or later, but that doesn't make it any easier to hear or deal with," says mightyoak on a Second Life message board. "I agree that until there's hard evidence that harmful data has been compromised, we should all remain calm. It's not going to be particularly comfortable waiting, though."

Aimee Weber, another Second Life user, raised the possibility that the hacker might link the real-world names with the pseudonyms assumed in the virtual world, and move from online "stalking" (an accepted practice online) to real-world stalking. More than 286,000 Second Lifers have logged onto the site in the last 60 days, according to site figures.

An investigation into the hack is ongoing, according to Linden Lab.

— Tim Wilson, Site Editor, Dark Reading

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Major Brazilian Bank Tests Homomorphic Encryption on Financial Data
Kelly Sheridan, Staff Editor, Dark Reading,  1/10/2020
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft Patches Windows Vuln Discovered by the NSA
Kelly Sheridan, Staff Editor, Dark Reading,  1/14/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-20003
PUBLISHED: 2020-01-17
Feldtech easescreen Crystal 9.0 Web-Services 9.0.1.16265 allows Stored XSS via the Debug-Log and Display-Log components. This could be exploited when an attacker sends an crafted string for FTP authentication.
CVE-2019-3686
PUBLISHED: 2020-01-17
openQA before commit c172e8883d8f32fced5e02f9b6faaacc913df27b was vulnerable to XSS in the distri and version parameter. This was reported through the bug bounty program of Offensive Security
CVE-2019-3683
PUBLISHED: 2020-01-17
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and...
CVE-2019-3682
PUBLISHED: 2020-01-17
The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.
CVE-2019-17361
PUBLISHED: 2020-01-17
In SaltStack Salt through 2019.2.0, the salt-api NEST API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.