Security Breach Found in Second Life Database

Published: Sep 11, 2006
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Linden Labs, the San Francisco-based creator of the virtual community Second Life, has told its users that their personal information could have been stolen due to a zero-day attack.

In a Sept. 8 announcement, the company said that users unencrypted names and addresses, as well as encrypted passwords and payment information, could have been exposed during the attack. The company, however, said that credit card information had not been exposed.

The security breach was first detected on Sept. 6, and Linden Labs said it repaired the problem immediately. A company investigation showed that hackers exploited third-party software used on the Second Life database to break into the servers.

“Due to the nature of the attack, the company cannot determine which individual data were exposed. The companys technical investigation is ongoing,” Linden Labs said in its release that was posted on the Second Life Web site.

Citing its own internal investigation, the company did not release many details about the breach besides acknowledging that it was a zero-day attack. The company is also still trying to determine what, if any, personal information was compromised.

Second Life is a virtual community that is maintained and run by its “residents,” who can make purchases through this online world and convert the “Linden dollar” into standard U.S. currency.

/zimages/2/28571.gifInternet-based threats using zero-day attacks are proliferating at a rapid pace.Click hereto read more.

Hacking into video games and virtual communities has become an increasing problem.

On Dec. 16, 2005, White Wolf Publishing, a company responsible for some of the most popular role-playing game brands, was forced to shut down its operations after international hackers exploited a software flaw and stole user data, including user names, e-mail addresses and encrypted passwords.

At the 2006 Black Hat conference, Greg Hoglund, a well-known security code expert, showed how he could beat an anti-cheating technology in the online role-playing game “World of Warcraft” by using rootkits he developed.

Advertisement

On its Web site, Linden Labs boasts that since 2003, when the community first opened, nearly 300,000 people from around the world have joined.

The company first noticed a problem on Sept. 6, when an unusual amount of activity found in the database logs showed that an attack had occurred. The initial internal investigation showed that the attack could have started as early as Sept. 3, but the company found no evidence of a compromise to the database until Sept. 5.

“On Sept., 8, 2006, we concluded that there was a substantial likelihood that customer account information could have been accessed,” the company said.

The company has invalided all user passwords, and members of the online community have been urged to reset their passwords and keep track of credit card statements and their PayPal accounts for irregularities. Additional updates will be posted on the companys blog.

/zimages/2/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Scott Ferguson

Scott Ferguson

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。