Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Fantasy Site Hack Exposes Data on 650,000 Users

Users of Second Life site forced to change passwords after zero-day exploit hits Web server

A hack on a popular Web fantasy site may have exposed the personal data of some 650,000 players, site operators revealed late last week.

Second Life, a virtual world in which players can live out another existence, was hit by a "zero-day exploit" last week, and a database containing players' names, addresses, passwords, and payment information was compromised, according to Linden Lab, which operates the site.

Systems administrators for Second Life voided all of the participants' passwords, forcing users to change to new passwords immediately. Users will have to answer a security question in order to get a new password.

Linden Lab was not specific about the details of the attack, and company officials did not reply to queries for this article. However, in messages to its customers, the company said the exploit was perpetrated on its Web server, via vulnerabilities in "third-party Web software."

So far, Linden Lab has been able only to determine the "aggregate size of the data that was downloaded through the intrusion," which appears to have been substantial. The company said it could not tell whether individual records were compromised, or which ones, which is why it decided to simply void all the passwords in the system and ask legitimate users to renew.

The database includes Second Life account names, real-life names, and contact information in unencrypted form, Linden Lab said. Account passwords and payment information (such as credit card numbers and PayPal transaction IDs) were also in the database but were encrypted via an MD-5 hash algorithm and "salt," which inserts additional data into the encryption pattern to make it harder to crack, the company said. A separate database that contained unencrypted credit card information was not compromised, according to Linden Lab.

"The compromised system was rebuilt and made more secure," Linden Lab said in its blog. The company plans to announce additional security improvements in the near future.

Second Life users, who log onto the site to buy virtual land, build virtual homes and try all sorts of pastimes they would never try in the real world, were frustrated by the intrusion.

"I've heard a number of people say it was bound to happen sooner or later, but that doesn't make it any easier to hear or deal with," says mightyoak on a Second Life message board. "I agree that until there's hard evidence that harmful data has been compromised, we should all remain calm. It's not going to be particularly comfortable waiting, though."

Aimee Weber, another Second Life user, raised the possibility that the hacker might link the real-world names with the pseudonyms assumed in the virtual world, and move from online "stalking" (an accepted practice online) to real-world stalking. More than 286,000 Second Lifers have logged onto the site in the last 60 days, according to site figures.

An investigation into the hack is ongoing, according to Linden Lab.

— Tim Wilson, Site Editor, Dark Reading

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25826
PUBLISHED: 2020-09-23
PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe.
CVE-2020-25821
PUBLISHED: 2020-09-23
** UNSUPPORTED WHEN ASSIGNED ** peg-markdown 0.4.14 has a NULL pointer dereference in process_raw_blocks in markdown_lib.c. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2020-3130
PUBLISHED: 2020-09-23
A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker to overwrite files on the underlying filesystem. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP re...
CVE-2020-3133
PUBLISHED: 2020-09-23
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The vulnerability is due to improper validation of incoming emails. An attacker could exploit t...
CVE-2020-3135
PUBLISHED: 2020-09-23
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based...