PDA

View Full Version : [ALERT] Hotmail hackedThousands of account details published online


CYBER WEESJE
10-06-2009, 04:55 AM
http://i.zdnet.com/blogs/liveid-login-zaw2.png


Hotmail hacked: Thousands of account details published online




Update (19:55 GMT): added statement from Microsoft at the end.

Thousands, perhaps tens of thousands of Hotmail accounts have been hacked through phishing sites and published online, according to the BBC.

The news is still breaking but according to Neowin, who first reported the story, Microsoft have enacted a rapid-response protocol to limit the damage.



According to Neowin:

“It appears only accounts used to access Microsoft’s Windows Live Hotmail have been posted, this includes @hotmail.com, @msn.com and @live.com accounts.

However, considering the Windows Live ID is a single sign-on solution for all Microsoft and Windows Live services, the implications could be a lot greater than first considered.

While phishing is relatively new in the grand scheme of online malware and threats, it seems the tens of thousands of users have mistaken a genuine login page for a fake one, and are now suffering the consequences.

This poses a question I have considered for some time now. There will no doubt be a number of students who have been a victim in this phishing campaign who have been sending and receiving important emails through the service, instead of their own university dedicated system.

Phishing often relies on the service targeted having a massive user base. In comparison to colleges and universities, Hotmail has a greater number of users worldwide, therefore the benefits reaped would be greater.



As a result, it is not clear whether users of Live@edu were targeted, considering the Windows Live ID sign-in process is identical to that of Hotmail. The potential, however, is very much there,

It is unclear at this time whether this is a “proof of concept” come protest-like attack, as the potential to take advantage of these accounts on a personal scale could be endless. But considering the details were published to the wider web, it seems to me it could be a way of alerting people to the consequences of phishing and/or the security of Hotmail.

With the simplicity of the Windows Live ID sign-in screen, to attempt to create a phishing site from this is surprisingly easy. However with the most recent browsers, a clear green bar or similar will indicate that in fact the sign-in screen is secure.

Nevertheless, it is an interesting story which may well see Microsoft bump up their security to Yahoo! anti-phishing standards.
Microsoft’s statement:

“Over the weekend Microsoft learned that several thousand Windows Live Hotmail customers’ credentials were exposed on a third-party site due to a phishing scheme. As always, upon learning of the issue, we immediately requested that the credentials be removed and launched an investigation to determine the impact to customers.

As part of that investigation, we determined that this was not a breach of internal Microsoft data and initiated our standard process of working to help customers regain control of their accounts.”

not the first this happend all those sites whit free gifts and stuf plus mirror links protected links you have to be very carefull these days even on twitter i now for a fact some of facebooks have bin removed for the same thing AND IT IS A GOOD THING TO CHANGE YOUR PASSWORD NOW

GRTZ CYBER WEESJE
ADMINISTRATOR@Wckediden

D/\SH
10-06-2009, 12:35 PM
damn thats insane... phising is just getting out of control these days.... seriously are you ever not be watched by big brother or someone else?

hctr68
10-06-2009, 01:11 PM
emailing is the way to get important info across to others and shoot hackers want that money they can get for giving out peoples info.

CYBER WEESJE
10-06-2009, 01:21 PM
damn thats insane... phising is just getting out of control these days.... seriously are you ever not be watched by big brother or someone else?

He bro yeah it is and selling account info of your hotmail logins and ip is expanding they make money whit it mirror links and protected links that look just like rapidlink think alot of freeprize sites do the same ohwell just think before you click link or register at some site think whe need some more Anonymous on the internet


GRTZ CYBER WEESJE
ADMINISTRATOR@Wckediden

wcked
10-06-2009, 01:37 PM
yea bro i can image that happening , plus msn is easy to hack form what i hear...thats why i always look at the site to make sure, it's the site that i visit.phising is a big issue now online

D/\SH
10-06-2009, 01:51 PM
yea i understand that guys but my point is what people do for money these days.... they dont care about anyone else or what hell it can bring to their lives if it can make them a penny

ronaldsdv
10-06-2009, 08:28 PM
man that's something else ....

menikfire
10-06-2009, 11:27 PM
MAN this is some crazy stuff man!!!
i agree with you D/\Sh its sad what people do now a day just for some money!!
not thinking of the people involve nor themself!!! crazy!!

wdbanks
10-07-2009, 12:12 AM
so how do you know if your one of the thousands who got hacked?

CYBER WEESJE
10-07-2009, 05:14 AM
so how do you know if your one of the thousands who got hacked?

Hi the best thing you can do is changed your password just to be safe


GRTZ CYBER WEESJE
ADMINISTRATOR@Wckediden

trentonmac
10-07-2009, 05:26 AM
Sucks for those who got hacked, but I can't feel too bad. My Paypal and 9 year old msn account got hacked into and now I'm dealing with lost money and lots of bounced check fees through my bank and the bastards changed my msn account and I can't use that anymore either. Hackers like this need to get a life.