Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

FOAK email hacking

20 views
Skip to first unread message

'Hog

unread,
Nov 19, 2009, 5:28:47 AM11/19/09
to
Extreme oddity.

Two people I know had their hotmail/live accounts hacked recently. There
have no shared acquaintances and live in different places. General
nuisance was caused by sending emails that had passed between them to
other people with malicious post editing.

We all hear of individual accounts being hacked but I'm struggling to
imagine how this could happen unless hotmail has a malicious techie?
both claim to have had strong passwords, changed occasionally.

Heard anything like it before?

Do Plod have a cybercrime department which deals with such things: i.e.
not just obsessed with kiddie porn

--
'Hog
'06 ST4-S
'96 Bastard12 '89 R100RS '81 XS650 '78 RD400
'81 R65 Outfit


B650

unread,
Nov 19, 2009, 5:38:34 AM11/19/09
to
On 19 Nov, 10:28, "'Hog" <sm911S...@hotmailCHIPS.co.uk> wrote:
> Extreme oddity.
>
> Two people I know had their hotmail/live accounts hacked recently. There
> have no shared acquaintances and live in different places. General
> nuisance was caused by sending emails that had passed between them to
> other people with malicious post editing.
>
> We all hear of individual accounts being hacked but I'm struggling to
> imagine how this could happen unless hotmail has a malicious techie?
> both claim to have had strong passwords, changed occasionally.
>
> Heard anything like it before?
>
> Do Plod have a cybercrime department which deals with such things: i.e.
> not just obsessed with kiddie porn
>

Probably signed up to some dodgy website using the same password as
the email account. I've had a number of emails from acquaintances
singing the praises of dodgy chinese electronics sites using less than
grammatically correct engrish.

Odd that the 'hacker' has just been causing mischief though, they
usually get put to money-making purposes.

No shared acquaintances, other than you? There's a logical conclusion
in there somewhere....

--
D

TOG@Toil

unread,
Nov 19, 2009, 6:18:55 AM11/19/09
to
On 19 Nov, 10:28, "'Hog" <sm911S...@hotmailCHIPS.co.uk> wrote:
> Extreme oddity.
>
> Two people I know had their hotmail/live accounts hacked recently. There
> have no shared acquaintances and live in different places. General
> nuisance was caused by sending emails that had passed between them to
> other people with malicious post editing.
>
> We all hear of individual accounts being hacked but I'm struggling to
> imagine how this could happen unless hotmail has a malicious techie?
> both claim to have had strong passwords, changed occasionally.
>
> Heard anything like it before?

No. What is odd is that it's the same behaviour applied to two totally
different hotmail accounts, and that the behaviour is essentially
harmless (when you consider what could have been done). That suggests
to me that it's the same perp, and that the perp is someone who knows
at least one of those people, is quite possibly considered a friend,
and that the two victims have been sloppy with security. Perhaps
logging on with the perp standing by, and the perp memorised one PW
and then managed to find the other.


>
> Do Plod have a cybercrime department which deals with such things: i.e.
> not just obsessed with kiddie porn
>

Yes, but they wouldn't care about this.

'Hog

unread,
Nov 19, 2009, 7:03:01 AM11/19/09
to

I rather tripped myself up at the beginning of the email. No shared
acquaintance other than me! But in fact I don't know one of them except
in passing. I'm sure it wasn't me <checks mirror and medication>

But is has just moved on this morning. Looks like it started on one side
of the equation, someone with a grudge who managed to guess a password.
They picked up on the 2nd victim by reading all the 1st victim's emails
I think. But how they gained access to that account is a mystery. I
don't think you can hack Hotmail with brute force.

Perhaps a child's name or somesuch that was mentioned in an email to
victim one.

TOG@Toil

unread,
Nov 19, 2009, 7:50:08 AM11/19/09
to
Hotmail is remarkably hard to hack. Yahoo used to be much easier: I
haven't for years. There used to be a Java vulnerability whereby you
could be copied in on all correspondence.

Once you've got one PW, it's remarkably easy to obtain more. It's like
picking a little hole in a sweater: all of a sudden the thing
unravels.

I'd still lay odds that the perp was/is known personally to the first
victim.

Krusty

unread,
Nov 19, 2009, 8:17:04 AM11/19/09
to
TOG@Toil wrote:

> On 19 Nov, 12:03, "'Hog" <sm911S...@hotmailCHIPS.co.uk> wrote:
> >
> > But is has just moved on this morning. Looks like it started on one
> > side of the equation, someone with a grudge who managed to guess a
> > password.
>

> I'd still lay odds that the perp was/is known personally to the first
> victim.

Well deduced Holmes.

--
Krusty

'03 Tiger 955i '02 MV Senna '96 Tiger (for sale)
'79 Fantic Hiro 250 (for sale) '81 Corvette (for sale)

TOG@Toil

unread,
Nov 19, 2009, 8:26:25 AM11/19/09
to
On 19 Nov, 13:17, "Krusty" <dontwant...@nowhere.invalid> wrote:
> TOG@Toil wrote:
> > On 19 Nov, 12:03, "'Hog" <sm911S...@hotmailCHIPS.co.uk> wrote:
>
> > > But is has just moved on this morning. Looks like it started on one
> > > side of the equation, someone with a grudge who managed to guess a
> > > password.
>
> > I'd still lay odds that the perp was/is known personally to the first
> > victim.
>
> Well deduced Holmes.
>
Well, uh, duh. But I don't mean that the email addie was harvested
from a guestbook or somesuch.

Beav

unread,
Nov 19, 2009, 11:45:13 AM11/19/09
to

"'Hog" <sm91...@hotmailCHIPS.co.uk> wrote in message
news:4b051ddc$0$2522$da0f...@news.zen.co.uk...

> Extreme oddity.
>
> Two people I know had their hotmail/live accounts hacked recently. There
> have no shared acquaintances and live in different places. General
> nuisance was caused by sending emails that had passed between them to
> other people with malicious post editing.
>
> We all hear of individual accounts being hacked but I'm struggling to
> imagine how this could happen unless hotmail has a malicious techie? both
> claim to have had strong passwords, changed occasionally.
>
> Heard anything like it before?
>
> Do Plod have a cybercrime department which deals with such things: i.e.
> not just obsessed with kiddie porn

You're obsessxed with bestiality porn too?


--
Beav

VN 750
Zed 1000
OMF# 19


'Hog

unread,
Nov 19, 2009, 2:50:39 PM11/19/09
to
TOG@Toil wrote:
> On 19 Nov, 13:17, "Krusty" <dontwant...@nowhere.invalid> wrote:
>> TOG@Toil wrote:
>>> On 19 Nov, 12:03, "'Hog" <sm911S...@hotmailCHIPS.co.uk> wrote:
>>
>>>> But is has just moved on this morning. Looks like it started on one
>>>> side of the equation, someone with a grudge who managed to guess a
>>>> password.
>>
>>> I'd still lay odds that the perp was/is known personally to the
>>> first victim.
>>
>> Well deduced Holmes.
>>
> Well, uh, duh. But I don't mean that the email addie was harvested
> from a guestbook or somesuch.

It was an ex friend with some sort of grudge. I'm trying to get them to
report it to Plod.

The Older Gentleman

unread,
Nov 19, 2009, 4:22:19 PM11/19/09
to
'Hog <sm91...@hotmailCHIPS.co.uk> wrote:

> It was an ex friend with some sort of grudge.

Told you.

> I'm trying to get them to
> report it to Plod.

Waste of time.


--
BMW K1100LT Ducati 750SS Honda CB400F Triumph Street Triple
Suzuki TS250ER GN250 Damn, back to six bikes!
Try Googling before asking a damn silly question.
chateau dot murray at idnet dot com

Cab

unread,
Nov 20, 2009, 3:54:21 AM11/20/09
to
On Nov 19, 11:28 am, "'Hog" <sm911S...@hotmailCHIPS.co.uk> wrote:
> Extreme oddity.
>
> Two people I know had their hotmail/live accounts hacked recently. There
> have no shared acquaintances and live in different places. General
> nuisance was caused by sending emails that had passed between them to
> other people with malicious post editing.
>
> We all hear of individual accounts being hacked but I'm struggling to
> imagine how this could happen unless hotmail has a malicious techie?
> both claim to have had strong passwords, changed occasionally.
>
> Heard anything like it before?
>
> Do Plod have a cybercrime department which deals with such things: i.e.
> not just obsessed with kiddie porn

I've recently seen a demo from one of the security experts in my
company and it's remarkably easy to get peoples email addies.

He set up a free hotspot with a commonly recognised name (call it X
but could be ANY free hotspot such as McDonalds, etc) and because he
used an access point that had stronger signal strength than the
regular access point, PC's automatically connected to his.

In the access point, there was a web server with an identical copy of
the X login page and a link to gmail (for example). Users would go
over to gmail and the welcome page was, again, identical to the gmail
login page. When the user entered the login/password, they were
redirected to the regular gmail page with all their emails, etc. What
users didn't know is that on the gmail login page, they had their
login/password harvested when they hit the submit button.

It's extremely easy to do and really isn't rocket science.
--
Cab

TOG@Toil

unread,
Nov 20, 2009, 4:58:36 AM11/20/09
to

Some people *cough* used to do something similar with Yahoo mail (but
not the hotspot) a few years ago. Redirect to an identical login page,
and harvest the username and PW. Incredibly basic stuff, as you say,
and superceded now, but it still works as a technique. And with the
refinement of a powerful hotspot, I can see it working perfectly.

Jim

unread,
Nov 20, 2009, 6:18:57 AM11/20/09
to
TOG@Toil wrote:
>> In the access point, there was a web server with an identical copy of
>> the X login page and a link to gmail (for example). Users would go
>> over to gmail and the welcome page was, again, identical to the gmail
>> login page. When the user entered the login/password, they were
>> redirected to the regular gmail page with all their emails, etc. What
>> users didn't know is that on the gmail login page, they had their
>> login/password harvested when they hit the submit button.
>>
>> It's extremely easy to do and really isn't rocket science.
>
> Some people *cough* used to do something similar with Yahoo mail (but
> not the hotspot) a few years ago. Redirect to an identical login page,
> and harvest the username and PW. Incredibly basic stuff, as you say,
> and superceded now, but it still works as a technique. And with the
> refinement of a powerful hotspot, I can see it working perfectly.

The solution to that is to use

https://gmail.com/

It's incredibly basic stuff.

Colin Irvine

unread,
Nov 20, 2009, 6:22:26 AM11/20/09
to
On Fri, 20 Nov 2009 00:54:21 -0800 (PST), Cab squeezed out the
following:

>I've recently seen a demo from one of the security experts in my
>company and it's remarkably easy to get peoples email addies.
>
>He set up a free hotspot with a commonly recognised name (call it X
>but could be ANY free hotspot such as McDonalds, etc) and because he
>used an access point that had stronger signal strength than the
>regular access point, PC's automatically connected to his.

I've used a couple of hotspots in cafes abroad for email. In every
case I had to get a password from behind the counter. I'm not saying
that's completely secure, but presumably it's at least safe from the
kind of harvesting you mention here. Or is it?

--
Colin Irvine
ZZR1400 BOF#33 BONY#34 COFF#06 BHaLC#5
http://www.colinandpat.co.uk

Cab

unread,
Nov 20, 2009, 7:38:51 AM11/20/09
to
On Nov 20, 12:22 pm, Colin Irvine <l...@bottom.of.home.page> wrote:
> On Fri, 20 Nov 2009 00:54:21 -0800 (PST), Cab squeezed out the
> following:
>
> >I've recently seen a demo from one of the security experts in my
> >company and it's remarkably easy to get peoples email addies.
>
> >He set up a free hotspot with a commonly recognised name (call it X
> >but could be ANY free hotspot such as McDonalds, etc) and because he
> >used an access point that had stronger signal strength than the
> >regular access point, PC's automatically connected to his.
>
> I've used a couple of hotspots in cafes abroad for email. In every
> case I had to get a password from behind the counter. I'm not saying
> that's completely secure, but presumably it's at least safe from the
> kind of harvesting you mention here. Or is it?

It's safer but you're still not immune. Even so, all a hacker needs to
do is set up an identical page which requests your login/password,
pretends to give you full internet access (without even worrying about
whether the login/password you've been provided with is valid or not)
and carries on doing the harvesting as I described above.

Even if you go to an https page, it's still possible to do the same.
In fact, you'd believe that you're more secure going to a https page
and will worry less about these sort of harvesting attempts.

GPRS connections (whilst not 100% secure) are actually much, much more
secure than bog standard wifi connections.

--
Cab

Cab

unread,
Nov 20, 2009, 7:39:18 AM11/20/09
to

I think you've missed the point.
--
Cab

Jim

unread,
Nov 20, 2009, 7:56:50 AM11/20/09
to
Cab wrote:
>> > Some people *cough* used to do something similar with Yahoo mail (but
>> > not the hotspot) a few years ago. Redirect to an identical login page,
>> > and harvest the username and PW. Incredibly basic stuff, as you say,
>> > and superceded now, but it still works as a technique. And with the
>> > refinement of a powerful hotspot, I can see it working perfectly.
>>
>> The solution to that is to use
>>
>> https://gmail.com/
>>
>> It's incredibly basic stuff.
>
> I think you've missed the point.

Why do you say that? The way certificate signing with HTTPS works is
specifically designed to prevent this kind of man-in-the-middle attack.
If the access point is subverted you'll get a certificate warning, which
is quite difficult to bypass with more recent browsers.

Mark Olson

unread,
Nov 20, 2009, 8:51:15 AM11/20/09
to
Cab wrote:

> Even if you go to an https page, it's still possible to do the same.
> In fact, you'd believe that you're more secure going to a https page
> and will worry less about these sort of harvesting attempts.

How does the hacker get around the certificate problem?

Cab

unread,
Nov 20, 2009, 4:43:24 PM11/20/09
to
On Fri, 20 Nov 2009 12:56:50 +0000, Jim wibbled:

Okay, but tell me, do you check every time when you go to gmail that the
login page is https? And, as I posted elsewhere, people don't always check
the validity of certificates (even if they have a bloody great warning page
pop up).

It's down to education though. But people don't generally receive security
training courses on internet and PC usage.

--
Cab :^) - "It's not a fookin' budgie, you daft tart!"
Z1000ABS : http://www.rosbif.org/ukrm (just for WUN)
The ALL NEW ukrm website : http://www.ukrm.info
email addy : ukrm_dot_cab_at_rosbif_dot_org

Cab

unread,
Nov 20, 2009, 4:39:11 PM11/20/09
to
On Fri, 20 Nov 2009 07:51:15 -0600, Mark Olson wibbled:

You'd be surprised at how many people accept invalid certificates or
don't look at the details of certificates to check their authenticity.

Most issues can be overcome with common sense.

Dr Ivan D. Reid

unread,
Nov 22, 2009, 7:49:59 AM11/22/09
to
On Fri, 20 Nov 2009 21:39:11 +0000, Cab <m...@privacy.net>
wrote in <vsejt6-...@news.rosbif.org>:

> On Fri, 20 Nov 2009 07:51:15 -0600, Mark Olson wibbled:
>> Cab wrote:

>>> Even if you go to an https page, it's still possible to do the same.
>>> In fact, you'd believe that you're more secure going to a https page
>>> and will worry less about these sort of harvesting attempts.

>> How does the hacker get around the certificate problem?

> You'd be surprised at how many people accept invalid certificates or
> don't look at the details of certificates to check their authenticity.

You'd be surprised at how many CERN pages I have to click past an
"invalid certificate" warning...



> Most issues can be overcome with common sense.

--
Ivan Reid, School of Engineering & Design, _____________ CMS Collaboration,
Brunel University. Ivan.Reid@[brunel.ac.uk|cern.ch] Room 40-1-B12, CERN
GSX600F, RG250WD "You Porsche. Me pass!" DoD #484 JKLO#003, 005
WP7# 3000 LC Unit #2368 (tinlc) UKMC#00009 BOTAFOT#16 UKRMMA#7 (Hon)
KotPT -- "for stupidity above and beyond the call of duty".

Mark Olson

unread,
Nov 22, 2009, 10:02:36 AM11/22/09
to
Dr Ivan D. Reid wrote:
> On Fri, 20 Nov 2009 21:39:11 +0000, Cab <m...@privacy.net>
> wrote in <vsejt6-...@news.rosbif.org>:
>> On Fri, 20 Nov 2009 07:51:15 -0600, Mark Olson wibbled:

>>> How does the hacker get around the certificate problem?


>
>> You'd be surprised at how many people accept invalid certificates or
>> don't look at the details of certificates to check their authenticity.
>
> You'd be surprised at how many CERN pages I have to click past an
> "invalid certificate" warning...

No doubt. I see invalid certificates on my company's (12.2B market cap)
intranet on a regular basis. But if I saw one on a McDonald's WiFi
hotspot (managed by AT&T) I'd pay attention.

Cab

unread,
Nov 23, 2009, 2:43:11 AM11/23/09
to
On Sun, 22 Nov 2009 09:02:36 -0600, Mark Olson wibbled:

Same in my co. Mind you, it's quite a small percentage of invalid
certificates compared to the number of https pages that they serve.

azza...@gmail.com

unread,
Apr 19, 2017, 6:39:12 PM4/19/17
to
Get results in one hour time for emails and other account:Change school grades,Erase criminal records,Hack bank accounts,phone clone,whatsapp and facebook hack,driver"s license,hack computer remotely,retrieval of lost files and documents,hack wifi network,expunge criminal records etc...contact:azza...@gmail.com

0 new messages