Thu Apr 3 00:56:18 2025
EVENTS
 FREE
SOFTWARE
INSTITUTE

POLITICS
JOBS
MEMBERS'
CORNER

MAILING
LIST

NYLXS Mailing Lists and Archives
NYLXS Members have a lot to say and share but we don't keep many secrets. Join the Hangout Mailing List and say your peice.

DATE 2024-09-01

HANGOUT

2025-04-03 | 2025-03-03 | 2025-02-03 | 2025-01-03 | 2024-12-03 | 2024-11-03 | 2024-10-03 | 2024-09-03 | 2024-08-03 | 2024-07-03 | 2024-06-03 | 2024-05-03 | 2024-04-03 | 2024-03-03 | 2024-02-03 | 2024-01-03 | 2023-12-03 | 2023-11-03 | 2023-10-03 | 2023-09-03 | 2023-08-03 | 2023-07-03 | 2023-06-03 | 2023-05-03 | 2023-04-03 | 2023-03-03 | 2023-02-03 | 2023-01-03 | 2022-12-03 | 2022-11-03 | 2022-10-03 | 2022-09-03 | 2022-08-03 | 2022-07-03 | 2022-06-03 | 2022-05-03 | 2022-04-03 | 2022-03-03 | 2022-02-03 | 2022-01-03 | 2021-12-03 | 2021-11-03 | 2021-10-03 | 2021-09-03 | 2021-08-03 | 2021-07-03 | 2021-06-03 | 2021-05-03 | 2021-04-03 | 2021-03-03 | 2021-02-03 | 2021-01-03 | 2020-12-03 | 2020-11-03 | 2020-10-03 | 2020-09-03 | 2020-08-03 | 2020-07-03 | 2020-06-03 | 2020-05-03 | 2020-04-03 | 2020-03-03 | 2020-02-03 | 2020-01-03 | 2019-12-03 | 2019-11-03 | 2019-10-03 | 2019-09-03 | 2019-08-03 | 2019-07-03 | 2019-06-03 | 2019-05-03 | 2019-04-03 | 2019-03-03 | 2019-02-03 | 2019-01-03 | 2018-12-03 | 2018-11-03 | 2018-10-03 | 2018-09-03 | 2018-08-03 | 2018-07-03 | 2018-06-03 | 2018-05-03 | 2018-04-03 | 2018-03-03 | 2018-02-03 | 2018-01-03 | 2017-12-03 | 2017-11-03 | 2017-10-03 | 2017-09-03 | 2017-08-03 | 2017-07-03 | 2017-06-03 | 2017-05-03 | 2017-04-03 | 2017-03-03 | 2017-02-03 | 2017-01-03 | 2016-12-03 | 2016-11-03 | 2016-10-03 | 2016-09-03 | 2016-08-03 | 2016-07-03 | 2016-06-03 | 2016-05-03 | 2016-04-03 | 2016-03-03 | 2016-02-03 | 2016-01-03 | 2015-12-03 | 2015-11-03 | 2015-10-03 | 2015-09-03 | 2015-08-03 | 2015-07-03 | 2015-06-03 | 2015-05-03 | 2015-04-03 | 2015-03-03 | 2015-02-03 | 2015-01-03 | 2014-12-03 | 2014-11-03 | 2014-10-03 | 2014-09-03 | 2014-08-03 | 2014-07-03 | 2014-06-03 | 2014-05-03 | 2014-04-03 | 2014-03-03 | 2014-02-03 | 2014-01-03 | 2013-12-03 | 2013-11-03 | 2013-10-03 | 2013-09-03 | 2013-08-03 | 2013-07-03 | 2013-06-03 | 2013-05-03 | 2013-04-03 | 2013-03-03 | 2013-02-03 | 2013-01-03 | 2012-12-03 | 2012-11-03 | 2012-10-03 | 2012-09-03 | 2012-08-03 | 2012-07-03 | 2012-06-03 | 2012-05-03 | 2012-04-03 | 2012-03-03 | 2012-02-03 | 2012-01-03 | 2011-12-03 | 2011-11-03 | 2011-10-03 | 2011-09-03 | 2011-08-03 | 2011-07-03 | 2011-06-03 | 2011-05-03 | 2011-04-03 | 2011-03-03 | 2011-02-03 | 2011-01-03 | 2010-12-03 | 2010-11-03 | 2010-10-03 | 2010-09-03 | 2010-08-03 | 2010-07-03 | 2010-06-03 | 2010-05-03 | 2010-04-03 | 2010-03-03 | 2010-02-03 | 2010-01-03 | 2009-12-03 | 2009-11-03 | 2009-10-03 | 2009-09-03 | 2009-08-03 | 2009-07-03 | 2009-06-03 | 2009-05-03 | 2009-04-03 | 2009-03-03 | 2009-02-03 | 2009-01-03 | 2008-12-03 | 2008-11-03 | 2008-10-03 | 2008-09-03 | 2008-08-03 | 2008-07-03 | 2008-06-03 | 2008-05-03 | 2008-04-03 | 2008-03-03 | 2008-02-03 | 2008-01-03 | 2007-12-03 | 2007-11-03 | 2007-10-03 | 2007-09-03 | 2007-08-03 | 2007-07-03 | 2007-06-03 | 2007-05-03 | 2007-04-03 | 2007-03-03 | 2007-02-03 | 2007-01-03 | 2006-12-03 | 2006-11-03 | 2006-10-03 | 2006-09-03 | 2006-08-03 | 2006-07-03 | 2006-06-03 | 2006-05-03 | 2006-04-03 | 2006-03-03 | 2006-02-03 | 2006-01-03 | 2005-12-03 | 2005-11-03 | 2005-10-03 | 2005-09-03 | 2005-08-03 | 2005-07-03 | 2005-06-03 | 2005-05-03 | 2005-04-03 | 2005-03-03 | 2005-02-03 | 2005-01-03 | 2004-12-03 | 2004-11-03 | 2004-10-03 | 2004-09-03 | 2004-08-03 | 2004-07-03 | 2004-06-03 | 2004-05-03 | 2004-04-03 | 2004-03-03 | 2004-02-03 | 2004-01-03 | 2003-12-03 | 2003-11-03 | 2003-10-03 | 2003-09-03 | 2003-08-03 | 2003-07-03 | 2003-06-03 | 2003-05-03 | 2003-04-03 | 2003-03-03 | 2003-02-03 | 2003-01-03 | 2002-12-03 | 2002-11-03 | 2002-10-03 | 2002-09-03 | 2002-08-03 | 2002-07-03 | 2002-06-03 | 2002-05-03 | 2002-04-03 | 2002-03-03 | 2002-02-03 | 2002-01-03 | 2001-12-03 | 2001-11-03 | 2001-10-03 | 2001-09-03 | 2001-08-03 | 2001-07-03 | 2001-06-03 | 2001-05-03 | 2001-04-03 | 2001-03-03 | 2001-02-03 | 2001-01-03 | 2000-12-03 | 2000-11-03 | 2000-10-03 | 2000-09-03 | 2000-08-03 | 2000-07-03 | 2000-06-03 | 2000-05-03 | 2000-04-03 | 2000-03-03 | 2000-02-03 | 2000-01-03 | 1999-12-03

Key: Value:

Key: Value:

MESSAGE
DATE 2024-09-07
FROM Ruben Safir
SUBJECT Subject: [Hangout - NYLXS] We are all fucked - Database Breach
krebsonsecurity.com
National Public Data Published Its Own Passwords
6–7 minutes

New details are emerging about a breach at National Public Data (NPD), a
consumer data broker that recently spilled hundreds of millions of
Americans’ Social Security Numbers, addresses, and phone numbers online.
KrebsOnSecurity has learned that another NPD data broker which shares
access to the same consumer records inadvertently published the
passwords to its back-end database in a file that was freely available
from its homepage until today.

In April, a cybercriminal named USDoD began selling data stolen from
NPD. In July, someone leaked what was taken, including the names,
addresses, phone numbers and in some cases email addresses for more than
272 million people (including many who are now deceased).

NPD acknowledged the intrusion on Aug. 12, saying it dates back to a
security incident in December 2023. In an interview last week, USDoD
blamed the July data leak on another malicious hacker who also had
access to the company’s database, which they claimed has been floating
around the underground since December 2023.

Following last week’s story on the breadth of the NPD breach, a reader
alerted KrebsOnSecurity that a sister NPD property — the background
search service recordscheck.net — was hosting an archive that included
the usernames and password for the site’s administrator.

A review of that archive, which was available from the Records Check
website until just before publication this morning (August 19), shows it
includes the source code and plain text usernames and passwords for
different components of recordscheck.net, which is visually similar to
nationalpublicdata.com and features identical login pages.

The exposed archive, which was named “members.zip,” indicates
RecordsCheck users were all initially assigned the same six-character
password and instructed to change it, but many did not.

According to the breach tracking service Constella Intelligence, the
passwords included in the source code archive are identical to
credentials exposed in previous data breaches that involved email
accounts belonging to NPD’s founder, an actor and retired sheriff’s
deputy from Florida named Salvatore “Sal” Verini.

Reached via email, Mr. Verini said the exposed archive (a .zip file)
containing recordscheck.net credentials has been removed from the
company’s website, and that the site is slated to cease operations “in
the next week or so.”

“Regarding the zip, it has been removed but was an old version of the
site with non-working code and passwords,” Verini told KrebsOnSecurity.
“Regarding your question, it is an active investigation, in which we
cannot comment on at this point. But once we can, we will [be] with you,
as we follow your blog. Very informative.”

The leaked recordscheck.net source code indicates the website was
created by a web development firm based in Lahore, Pakistan called
creationnext.com, which did not return messages seeking comment.
CreationNext.com’s homepage features a positive testimonial from Sal Verini.

A testimonial from Sal Verini on the homepage of CreationNext, the
Lahore, Pakistan-based web development firm that apparently designed NPD
and RecordsCheck.

There are now several websites that have been stood up to help people
learn if their SSN and other data was exposed in this breach. One is
npdbreach.com, a lookup page erected by Atlas Data Privacy Corp. Another
lookup service is available at npd.pentester.com. Both sites show NPD
had old and largely inaccurate data on Yours Truly.

The best advice for those concerned about this breach is to freeze one’s
credit file at each of the major consumer reporting bureaus. Having a
freeze on your files makes it much harder for identity thieves to create
new accounts in your name, and it limits who can view your credit
information.

A freeze is a good idea because all of the information that ID thieves
need to assume your identity is now broadly available from multiple
sources, thanks to the multiplicity of data breaches we’ve seen
involving SSN data and other key static data points about people.

Screenshots of a Telegram-based ID theft service that was selling
background reports using hacked law enforcement accounts at USInfoSearch.

There are numerous cybercriminal services that offer detailed background
checks on consumers, including full SSNs. These services are powered by
compromised accounts at data brokers that cater to private investigators
and law enforcement officials, and some are now fully automated via
Telegram instant message bots.

In November 2023, KrebsOnSecurity wrote about one such service, which
was being powered by hacked accounts at the U.S. consumer data broker
USInfoSearch.com. This is notable because the leaked source code
indicates Records Check pulled background reports on people by querying
NPD’s database and records at USInfoSearch. KrebsOnSecurity sought
comment from USInfoSearch and will update this story if they respond.

The point is, if you’re an American who hasn’t frozen their credit files
and you haven’t yet experienced some form of new account fraud, the ID
thieves probably just haven’t gotten around to you yet.

All Americans are also entitled to obtain a free copy of their credit
report weekly from each of the three major credit bureaus. It used to be
that consumers were allowed one free report from each of the bureaus
annually, but in October 2023 the Federal Trade Commission announced the
bureaus had permanently extended a program that lets you check your
credit report once a week for free.

If you haven’t done this in a while, now would be an excellent time to
order your files. To place a freeze, you’ll need to create an account at
each of the three major reporting bureaus, Equifax, Experian and
TransUnion. Once you’ve established an account, you should be able to
then view and freeze your credit file. If you spot errors, such as
random addresses and phone numbers you don’t recognize, do not ignore
them. Dispute any inaccuracies you may find.

--
So many immigrant groups have swept through our town
that Brooklyn, like Atlantis, reaches mythological
proportions in the mind of the world - RI Safir 1998
http://www.mrbrklyn.com
DRM is THEFT - We are the STAKEHOLDERS - RI Safir 2002

http://www.nylxs.com - Leadership Development in Free Software
http://www.brooklyn-living.com

Being so tracked is for FARM ANIMALS and extermination camps,
but incompatible with living as a free human being. -RI Safir 2013
_______________________________________________
Hangout mailing list
Hangout-at-nylxs.com
http://lists.mrbrklyn.com/mailman/listinfo/hangout

  1. 2024-09-02 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] hunting
  2. 2024-09-03 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] The Inlfation fall out from COVID-19 mismanagement
  3. 2024-09-05 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] jobs
  4. 2024-09-05 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] hyper inflation...
  5. 2024-09-06 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] =?utf-8?b?4oCYT3Vy4oCZIE5hdGlvbmFsIEhlYWx0aCBT?=
  6. 2024-09-06 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] [nj-at-nj.pcsjobs.org: Shortcut to a Lucrative
  7. 2024-09-06 mayer ilovitz <pmamayeri-at-gmail.com> Re: [Hangout - NYLXS] [nj-at-nj.pcsjobs.org: Shortcut to a Lucrative
  8. 2024-09-06 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] [nj-at-nj.pcsjobs.org: Shortcut to a Lucrative
  9. 2024-09-06 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] [nj-at-nj.pcsjobs.org: Shortcut to a Lucrative
  10. 2024-09-06 Ruben Safir <mrbrklyn-at-panix.com> Subject: [Hangout - NYLXS] [missbelmar-aol.com-at-shared1.ccsend.com: ALL OUT
  11. 2024-09-07 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Facebook Oversite commitee potmarked with
  12. 2024-09-07 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] What real war crimes looks like
  13. 2024-09-07 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Lanny Smoot, Hero of Brooklyn
  14. 2024-09-07 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] We are all fucked - Database Breach
  15. 2024-09-02 Gabor Szabo <gabor-at-szabgab.com> Subject: [Hangout - NYLXS] [Perlweekly] #684 - Perl and Corinna
  16. 2024-09-03 From: "Free Software Foundation" <info-at-fsf.org> Subject: [Hangout - NYLXS] Free Software Supporter -- Issue 197,
  17. 2024-09-08 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] [nj-at-nj.pcsjobs.org: PCS Open House Schedule For
  18. 2024-09-11 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] [info-at-poelgroupstaffing.com: Re: a suitable
  19. 2024-09-11 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] [info-at-poelgroupstaffing.com: Re: a suitable
  20. 2024-09-11 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] [info-at-poelgroupstaffing.com: Re: a suitable
  21. 2024-09-11 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] [info-at-poelgroupstaffing.com: Re: a suitable
  22. 2024-09-13 mayer ilovitz <pmamayeri-at-gmail.com> Subject: [Hangout - NYLXS] Henry Morgenthau film spotlights US antisemitism
  23. 2024-09-14 Ruben Safir <ruben-at-mrbrklyn.com> Re: [Hangout - NYLXS] Coumo consipracies
  24. 2024-09-16 Gabor Szabo <gabor-at-szabgab.com> Subject: [Hangout - NYLXS] [Perlweekly] #686 - Perl Conference
  25. 2024-09-25 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] [info-at-poelgroupstaffing.com: We staff top
  26. 2024-09-29 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] The FBI is so out of control
  27. 2024-09-30 Gabor Szabo <gabor-at-szabgab.com> Subject: [Hangout - NYLXS] [Perlweekly] #688 - Perl and Hacktoberfest
  28. 2024-09-26 From: "APhA - American Pharmacists Association" Subject: [Hangout - NYLXS] Submit your abstract for APhA2025 now!

NYLXS are Do'ers and the first step of Doing is Joining! Join NYLXS and make a difference in your community today!