Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Fantasy Site Hack Exposes Data on 650,000 Users

Users of Second Life site forced to change passwords after zero-day exploit hits Web server

A hack on a popular Web fantasy site may have exposed the personal data of some 650,000 players, site operators revealed late last week.

Second Life, a virtual world in which players can live out another existence, was hit by a "zero-day exploit" last week, and a database containing players' names, addresses, passwords, and payment information was compromised, according to Linden Lab, which operates the site.

Systems administrators for Second Life voided all of the participants' passwords, forcing users to change to new passwords immediately. Users will have to answer a security question in order to get a new password.

Linden Lab was not specific about the details of the attack, and company officials did not reply to queries for this article. However, in messages to its customers, the company said the exploit was perpetrated on its Web server, via vulnerabilities in "third-party Web software."

So far, Linden Lab has been able only to determine the "aggregate size of the data that was downloaded through the intrusion," which appears to have been substantial. The company said it could not tell whether individual records were compromised, or which ones, which is why it decided to simply void all the passwords in the system and ask legitimate users to renew.

The database includes Second Life account names, real-life names, and contact information in unencrypted form, Linden Lab said. Account passwords and payment information (such as credit card numbers and PayPal transaction IDs) were also in the database but were encrypted via an MD-5 hash algorithm and "salt," which inserts additional data into the encryption pattern to make it harder to crack, the company said. A separate database that contained unencrypted credit card information was not compromised, according to Linden Lab.

"The compromised system was rebuilt and made more secure," Linden Lab said in its blog. The company plans to announce additional security improvements in the near future.

Second Life users, who log onto the site to buy virtual land, build virtual homes and try all sorts of pastimes they would never try in the real world, were frustrated by the intrusion.

"I've heard a number of people say it was bound to happen sooner or later, but that doesn't make it any easier to hear or deal with," says mightyoak on a Second Life message board. "I agree that until there's hard evidence that harmful data has been compromised, we should all remain calm. It's not going to be particularly comfortable waiting, though."

Aimee Weber, another Second Life user, raised the possibility that the hacker might link the real-world names with the pseudonyms assumed in the virtual world, and move from online "stalking" (an accepted practice online) to real-world stalking. More than 286,000 Second Lifers have logged onto the site in the last 60 days, according to site figures.

An investigation into the hack is ongoing, according to Linden Lab.

— Tim Wilson, Site Editor, Dark Reading

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/17/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5421
PUBLISHED: 2020-09-19
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
CVE-2020-8225
PUBLISHED: 2020-09-18
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
CVE-2020-8237
PUBLISHED: 2020-09-18
Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.
CVE-2020-8245
PUBLISHED: 2020-09-18
Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11....
CVE-2020-8246
PUBLISHED: 2020-09-18
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-W...