2013-10-24_0047It was recently reported that a hacking group calling itself ‘TeamBerserk’ reported via Twitter that, they have stolen $100,000 from peoples bank accounts after using SQL Injection to hack into a California Internet Service Provider’s database and download all their customers user names and passwords.

SQL Injection is one of the most common security vulnerabilities on the Internet.  But it can only be successful when the web application it’s launched against is not sufficiently secured.  This is where keeping your WordPress site updated becomes so critical.  The updates to plugins, themes, and WordPress itself patch holes that hackers have discovered where they can utilize these exploits and gain access to things like your database.

Video proof was uploaded which shows how the hackers used SQL Injection to gain access to the ISP’s database and download email addresses, user names, and unencrypted passwords.

Using SQLmap, an automated SQL Injection Tool, hackers took less then 15 minutes to gain access to the Customer data base at the ISP and download it.  They then took at random one persons username and relative password and used it at Paypal, gmail, and even Citibank account logins and it worked, simply because the victim used the same password at all the websites.

After all it’s so hard to remember multiple passwords pretty much everyone uses the same one everywhere they go online.  I know I used to, and I’ll bet you still do.  But this shows why, at the very least, you should use different and strong passwords at any sites where your personal or financial information is stored.  Bank accounts, credit cards, etc., should all have solid and individual passwords.

And it’s easy to keep track of passwords if you use a reliable plugin to help with the task.  I use LastPass which is a Free tool and very easy to work with.

So if you have the same password that you use for blogging, Facebook and the like on your bank and credit card logins now might be a good time to think about changing them.

