<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>security breach — LowEndSpirit DEV</title>
        <link>https://dev.lowendspirit.com/index.php?p=/</link>
        <pubDate>Thu, 04 Jun 2026 18:50:32 +0000</pubDate>
        <language>en</language>
            <description>security breach — LowEndSpirit DEV</description>
    <atom:link href="https://dev.lowendspirit.com/index.php?p=/discussions/tagged/security-breach/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>GoDaddy WordPress Hosting breach -2021 edition</title>
        <link>https://dev.lowendspirit.com/index.php?p=/discussion/3540/godaddy-wordpress-hosting-breach-2021-edition</link>
        <pubDate>Mon, 22 Nov 2021 23:11:45 +0000</pubDate>
        <category>Industry News</category>
        <dc:creator>vyas</dc:creator>
        <guid isPermaLink="false">3540@/index.php?p=/discussions</guid>
        <description><![CDATA[<p><a href="https://www.wordfence.com/blog/2021/11/godaddy-breach-plaintext-passwords/" rel="nofollow">https://www.wordfence.com/blog/2021/11/godaddy-breach-plaintext-passwords/</a></p>

<p>Excerpt</p>

<p>What did the attacker have access to?</p>

<p>The SEC filing indicates that the attacker had access to user email addresses and customer numbers, the original WordPress Admin password that was set at the time of provisioning, and SSL private keys. All of these could be of use to an attacker, but one item, in particular, stands out:</p>

<p>During the period from September 6, 2021, to November 17, 2021, the sFTP and database usernames and passwords of active customers were accessible to the attacker.</p>

<p>GoDaddy stored sFTP passwords in such a way that the plaintext versions of the passwords could be retrieved, rather than storing salted hashes of these passwords, or providing public key authentication, which are both industry best practices.</p>
]]>
        </description>
    </item>
   </channel>
</rss>
