250k users exposed in Naijaloaded hack

Databases stolen.

Almost 250,000 user details of popular Nigerian youth forum Naijaloaded have been exposed after the site was hacked.

A hacker by the name of TheMrX uploaded a shell on the website and accessed its 42mb user database.

 


The database contained names, usenames, passwords and location information of 243,089 users.

Naijaloaded is a popular African social forum site that includes hacking and software tutorials, and discussion on music, movies and business.

The hackers said they would not publish the database, seen by SC Magazine, but said the US HostGator webserver that hosted Naijaloaded contained 79 other domains that may be vulnerable.

"It is running one of the newest 2011 kernals, so most public exploits are outdated yet, it may still be possible to get in," a member of the Team Infra hacking group said.

The hacker also showed two invoice databases with customer email exchanges and sales data purportedly held by hosting providers urhostz.com and betarack.com.

 

The group said the data was obtained through a local file inclusion exploit in the WHMCS client management and billing system.

Copyright © SC Magazine, Australia

250k users exposed in Naijaloaded hack
Technology

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read