Status
Not open for further replies.
Just to note, I haven't been given a new password yet. Heading off to support to do it now. They're probably taking their time with this to make sure they're not opening themselves up to a second-wave attack.



No, this is probably the old service provider that they used for the portal last time getting compromised the same way. The dumped data, and the service used for the paste, implies that it's all done by the same person in the same way.

This is all new information...after the old one got shutdown.
 
This is all new information...after the old one got shutdown.

He's referring to the method applied, which was probably the same method as used before. You can get current information with the same method, if it's a database query or something, with compromised credentials.
 
He's referring to the method applied, which was probably the same method as used before. You can get current information with the same method, if it's a database query or something, with compromised credentials.

Yah but that means CW was lying to us...

They claimed the hack happened at a third party which had accumulated the data. That third party was allegedly cut off from their services and then passwords were reset.

So what's the truth really?
 
He's referring to the method applied, which was probably the same method as used before. You can get current information with the same method, if it's a database query or something, with compromised credentials.

Yup. The thing that is new is the name left to credit the hack, and the following:

by the South African Post Office

Still to come: banking details, addresses, ID numbers and more :)

media? [email protected]

... was at the top of the paste. The paste's name is also "Crystal Web - Strike 3".

Edit: Here's a comforting thought - CW doesn't host mail inboxes using your DSL username. That would have been a disaster if those services were in place.
 
Last edited:
Yah but that means CW was lying to us...

They claimed the hack happened at a third party which had accumulated the data. That third party was allegedly cut off from their services and then passwords were reset.

So what's the truth really?
It depends how it was hacked, and if the method used, was exactly the same as the previous times. If it is the same method, then there is somewhere an issue still on the CW side.

One would assume that, because its a 3rd time, that the person/s could be an employee or an ex one who knows the system?

Hopefully CW rep dude will be on shortly to explain what is happening
 
It depends how it was hacked, and if the method used, was exactly the same as the previous times. If it is the same method, then there is somewhere an issue still on the CW side.

One would assume that, because its a 3rd time, that the person/s could be an employee or an ex one who knows the system?

Hopefully CW rep dude will be on shortly to explain what is happening

In my opinion if something like this happens twice in the same manner...then it's negligence on CW's part.

Then I feel the hacker is almost justified in proving his point.
 
Yah but that means CW was lying to us...

They claimed the hack happened at a third party which had accumulated the data. That third party was allegedly cut off from their services and then passwords were reset.

So what's the truth really?

I don't know what they said, I just know it's data from 23 June or later, because that's when my password was last changed due to the previous hack, and it's on there.
 
In my opinion if something like this happens twice in the same manner...then it's negligence on CW's part.

Then I feel the hacker is almost justified in proving his point.

Fully agreed. And I just told Live Support as much.

Interestingly, they weren't aware of it yet.
 
I was on the old hack list but I left CW for another "he who should not be named" about October last year. I joined CW again July. I never got a mail. Maybe the hack took place months again and he was sitting on the info?
 
In my opinion if something like this happens twice in the same manner...then it's negligence on CW's part.

Then I feel the hacker is almost justified in proving his point.
For sure, but we still dont know if the system was hacked along the same path, or if this was a completely different entry.

If it was a different method, along a completely different path within the CW systems, then that is a big concern.

I would assume, that the previous holes were patched, but if it was, and they still got through, then that will be a concern.
 
I was on the old hack list but I left CW for another "he who should not be named" about October last year. I joined CW again July. I never got a mail. Maybe the hack took place months again and he was sitting on the info?

By July, you mean 1 July?

If so, that narrows the timeline down to between 23rd and 30th of June...
 
I don't know what they said, I just know it's data from 23 June or later, because that's when my password was last changed due to the previous hack, and it's on there.
Did you change your password, immediately after CW changed it? Or did you leave it as is? If you did change, and this current list still shows the password CW changed it to, then could this be more a warning, rather than current passwords?
 
Did you change your password, immediately after CW changed it? Or did you leave it as is? If you did change, and this current list still shows the password CW changed it to, then could this be more a warning, rather than current passwords?

I didn't change it because they already changed it, so I saw no need.
 
I hope CrystalWeb appreciates the seriousness of this. Whilst I can understand that stuff like that happens, twice in 3 months is a bit uncalled for. I wasn't concerned at all after the first time, but now the alarm bells are ringing.
 
Did you change your password, immediately after CW changed it? Or did you leave it as is? If you did change, and this current list still shows the password CW changed it to, then could this be more a warning, rather than current passwords?

While a lot of the passwords are randomly generated, some are user-chosen. So, probably not.

Edit: Support is swamped this morning with password change requests and such. My guy is probably running between 10 conversations now.
 
Last edited:
I am quite sure CW defended the last hack claiming some third party provider was compromised.

Then CW promised they have dealt with it - and we will be suprised to hear who else got hacked.

They were lambasted for storing passwords in plain text, they promised this will not be the case going forward.

Good intentions are all fine and well, but take for example my brother (stupidly) uses the same password for his online banking as with CW. Have now educated him on this.

All in all this is a very very poor showing by CW.

I will have to dig up previous communication - but this is how I remember events.
 
In my opinion if something like this happens twice in the same manner...then it's negligence on CW's part.

Then I feel the hacker is almost justified in proving his point.
No the hacker is not justified.

A whitehat would inform CW with respect to the vulnerability found not spread fear, uncertainty and doubt.
 
While a lot of the passwords are randomly generated, some are user-chosen. So, probably not.

Edit: Support is swamped this morning with password change requests and such. My guy is probably running between 10 conversations now.

I was told they do not have the ability to change the password to a password of my choice when I asked this morning. The new password was randomly generated and sent to me via SMS.
 
I was told they do not have the ability to change the password to a password of my choice when I asked this morning. The new password was randomly generated and sent to me via SMS.

And I was told that I'd have to be manually moved over to the new infrastructure before getting a new password. So it's quite possible that the passwords that have been leaked are all from the old infrastructure, because it was still possible to specify your own password back then, IIRC.
 
Status
Not open for further replies.
Top
Sign up to the MyBroadband newsletter
X