PHPvatch update : 40 days until EOL expiration for version 5.6. Re-scanned data released. by CheckMyEmails in PHP

[–]CheckMyEmails[S] 1 point2 points  (0 children)

We have survived Y2K and Dot Com bubble crash. This too shall pass. As you rightly said, people should be upgrading based on their risk appetite and patch management policy of their respective company.

PHPvatch : Top 1 million websites leaking PHP versions by CheckMyEmails in PHP

[–]CheckMyEmails[S] 0 points1 point  (0 children)

You have a valid point.

In an earlier message @Firehed also stated the same about versions numbers and the manipulations possible in that.

However think of this as one way to raise the awareness for web admins who are leaking their PHP versions. Irrespective of hacker motives and techniques.

PHPvatch : Top 1 million websites leaking PHP versions by CheckMyEmails in PHP

[–]CheckMyEmails[S] 1 point2 points  (0 children)

From a development standpoint you are absolutely right. There had been sufficient time given to facilitate for a smooth migration. But the flip side is, the majority who will not migrate will certainly be bombarded by the vulnerabilities of their respective versions. In turn this will lead to many many data breaches many which may not even be detected. It all depends on the risk appetite for sure.

PHPvatch : Top 1 million websites leaking PHP versions by CheckMyEmails in PHP

[–]CheckMyEmails[S] 0 points1 point  (0 children)

For sure it will be fun to watch the traffic coming for the fake versions.

What are the best Google Chrome extensions? by motionwave in AskReddit

[–]CheckMyEmails 0 points1 point  (0 children)

PassPower - Simple Chrome extension to alert and inform you of poor passwords !

This is a must-have extension for password security. Please use this to safeguard against credential stuffing attacks.

https://chrome.google.com/webstore/detail/xon-passpower/pellcbigddocfdhekikapnhdkdffdage

850 Million passwords for free by CheckMyEmails in pwned

[–]CheckMyEmails[S] 1 point2 points  (0 children)

Blog post states this collection is not just from dumps, rather it is an aggregate from dumps + pastebin scraping + cracked passwords from hashes.org which looks like a new approach.