Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

MSN Hotmail password hacking.

Thread Tools
 
Search this Thread
 
Old 30 January 2004, 02:22 PM
  #1  
Johnny50
Scooby Regular
Thread Starter
 
Johnny50's Avatar
 
Join Date: Apr 2003
Location: Scotland
Posts: 5,389
Likes: 0
Received 0 Likes on 0 Posts
Angry

Hi there.

Someone has managed to change my hotmail account password.

This is the second time it has happened.

Is there anything i can do to prevent this, and find out who is doing it ?
I've got nothing of interest in my account, but it's rather annoying.

Thanks
Johnny
Old 30 January 2004, 04:00 PM
  #2  
StickyMicky
Scooby Regular
 
StickyMicky's Avatar
 
Join Date: Feb 2003
Location: Zed Ess Won Hay Tee
Posts: 21,611
Likes: 0
Received 0 Likes on 0 Posts
Post

stop haveing a easy to guess secret question??

i used to have "what colour is my car" how daft was that
Old 30 January 2004, 04:03 PM
  #3  
Mr.Cookie
Scooby Regular
 
Mr.Cookie's Avatar
 
Join Date: Apr 2000
Location: www.mrcookie.co.uk
Posts: 5,757
Likes: 0
Received 0 Likes on 0 Posts
Post

StickyMicky


Depends was your email addy man_with_blue_car@hotmail.com

Si
Ps blue is a guess folks just incase he's not changed password
Old 30 January 2004, 04:05 PM
  #4  
Mr.Cookie
Scooby Regular
 
Mr.Cookie's Avatar
 
Join Date: Apr 2000
Location: www.mrcookie.co.uk
Posts: 5,757
Likes: 0
Received 0 Likes on 0 Posts
Post

Johnny

Do you log into msn anywhere like internet cafe, work where other people can use pc etc etc

Si
Old 30 January 2004, 04:59 PM
  #5  
lightning101
Scooby Regular
 
lightning101's Avatar
 
Join Date: Oct 2004
Location: Never do names esp. Joey, spaz or Mong
Posts: 39,688
Likes: 0
Received 0 Likes on 0 Posts
Post

If you set up another hotmail account - then use a small hack from astalvista.com - you can get into any hotmail account - ALLEGEDLY.
Old 30 January 2004, 05:16 PM
  #6  
scatter_wrx
Scooby Regular
 
scatter_wrx's Avatar
 
Join Date: Aug 2003
Posts: 79
Likes: 0
Received 0 Likes on 0 Posts
Post

Do you use the password reminder (i.e. the Forgotton your password" link)? If you do, then make sure it's not an easy answer to the question.

For example:
Reminder Q: What is the best premiership footie team?
Answer: Chelsea

Anyone would get that right & then be able to change your password!
Old 30 January 2004, 05:19 PM
  #7  
StickyMicky
Scooby Regular
 
StickyMicky's Avatar
 
Join Date: Feb 2003
Location: Zed Ess Won Hay Tee
Posts: 21,611
Likes: 0
Received 0 Likes on 0 Posts
Post

mr cookie, no its not

m1ckyowens@hot
etc etc

but theres plenty of people who could easily find out my cars colour (it was my old vectra)

one person who was a regular actualy changed my password while messing about, hes a honest kid, and apoligised and told me (probs read all my **** mails tho )

then he showed me how it was done, i set that secret question a long long time ago when i 1st got online, the problem was all my fackin cars have been white lmao, he told me the new password i thanked him and chanegd the question to sumthing else (whats my first name )
lol
Old 30 January 2004, 06:16 PM
  #8  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Post

It's going to be one of a few things

1) you've logged into MSN somewhere and the account has been left logged in and someone has changed it

2) somone has supplied the corect information andcorrect answer to your secret question. Seem to remember they use your birtday or postcode as verification so when you change your details put in a bogus birthday/postcode, obvisouly remembering what you did put in

3) someone is using a hacking prog to get in.

I think 1 and 2 are more likely than 3 though.
Old 30 January 2004, 07:58 PM
  #9  
ianmiller999
Scooby Regular
 
ianmiller999's Avatar
 
Join Date: Feb 2003
Posts: 1,285
Likes: 0
Received 0 Likes on 0 Posts
Post

Somebody I know thought it would be funny to mess up my hotmail account before, to the stage where it said that the email address did not exist. But as I knew who had done it, I threatened them with a major beating if they didn't sort it and lo and behold my account worked 5 minutes later.

Never found out how he did it.
Old 30 January 2004, 08:05 PM
  #10  
ianmiller999
Scooby Regular
 
ianmiller999's Avatar
 
Join Date: Feb 2003
Posts: 1,285
Likes: 0
Received 0 Likes on 0 Posts
Post

Just found a programme which claims:

Written in Delphi 6, this trojan exploits the MSN Logging feature on MSN 6 Beta (at the time of writing). Once infected, a machine can be connected to with the client, and all conversation logs from any account used at that machine, can be downloaded. In addition to this, the server is totally undetectable, halts many firewall/AV systems, and allows E-Mail and ICQ Notification of the victims IP Address. Also, if the user disables Message logging on this machine, everytime the server receives a signal from the client.
Old 31 January 2004, 07:57 AM
  #11  
Johnny50
Scooby Regular
Thread Starter
 
Johnny50's Avatar
 
Join Date: Apr 2003
Location: Scotland
Posts: 5,389
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

Thanks for all these replys fellas.

Yep, the answer to the secret question aint hard...
But i never log on in a public place...always at work.

Cant be anyone there, i can guarantee that.

I rekon i'll change my secret question to something completely obscure.

THanks again

Johnny
Old 31 January 2004, 10:07 AM
  #12  
Gedi
Scooby Regular
 
Gedi's Avatar
 
Join Date: Jan 2003
Posts: 932
Likes: 0
Received 0 Likes on 0 Posts
Post

Its really not as easy as people think to directly gain access to hotmail (etc) accounts.

We get questions about hacking hotmail quite often both as a hacking magazine and IRC security channels (#hackuk etc....plug heheh) and usually ignore/flame/ban them. But this is deffinitely an exception as your on the other side of the fence.

Accounts are usually compromised via other means like social engineering, not in the way most people think.

On this occasion, (assuming you haven't fallen for SE tricks) I would guess you could be zombied. This is only a guess, as its impossible to say without analysing the machine.

Do you check for outbound connections on your machine?

Old 31 January 2004, 10:16 AM
  #13  
jason4656
Scooby Regular
 
jason4656's Avatar
 
Join Date: Nov 2003
Location: EVO X 400/400
Posts: 1,278
Likes: 0
Received 0 Likes on 0 Posts
Post

there is only one way as far as i know, it works something like this

1 you go to the page where it says relogin to hotmail, save that page as in ur computer.

you then host a certain type of software setup(wont mention who) which running mdb and asp you can do a little editing of the html and make that page look like the person whos email you want to steal is logging in.

So then the software will generate and send mail using cdonts although the headers are identifiable, most people wont check this so you can make the mail look like it came from anywhere you want.

So you send an email saying, "msn greeting card" something like that, the user clicks on the link, which is actually on ur server(this is osmething you have to disguise, using long folder names i found was best as new ie6 security patches exposes you) then when the user types in their password, its taken, and the page they were previously looking at is deactivated, so if they click the link again to see if anything is suspicious, the page is gone.

I actually tried this(with permission of course) and i did manage with a few goes, to get it to work, however if you dont have web hosting knowledge and some asp/html experience i wouldnt even bother

Old 31 January 2004, 10:50 AM
  #14  
Gedi
Scooby Regular
 
Gedi's Avatar
 
Join Date: Jan 2003
Posts: 932
Likes: 0
Received 0 Likes on 0 Posts
Post

there is only one way as far as i know
Many many more.

I remember first seeing a variant to that method in either phrack or 2600 in the nid 90's
Old 31 January 2004, 10:55 AM
  #15  
jason4656
Scooby Regular
 
jason4656's Avatar
 
Join Date: Nov 2003
Location: EVO X 400/400
Posts: 1,278
Likes: 0
Received 0 Likes on 0 Posts
Post

ok then one that works, there are lots of so called keystroke loggers but you have to get someone to accept files over msn or whatever, that way you are in control and unless the person is really clued up, it will work
Old 31 January 2004, 12:36 PM
  #16  
scunnered
Scooby Regular
iTrader: (1)
 
scunnered's Avatar
 
Join Date: Sep 2002
Location: Ayrshire
Posts: 1,199
Likes: 0
Received 8 Likes on 8 Posts
Post

On the mention of keyloggers, could it be possible that your IT dept. has a version of this in place, and one of the IT people might be having a bit of fun at your expense.
Old 31 January 2004, 05:02 PM
  #17  
R1916v
Scooby Regular
 
R1916v's Avatar
 
Join Date: May 2002
Posts: 1,002
Likes: 0
Received 0 Likes on 0 Posts
Post

If th ecompany uses decent weblogging software they won't need keyloggers, ours logs absoutely every click and keyboard press a user does on a website
Old 31 January 2004, 05:17 PM
  #18  
Scooby96
Scooby Regular
 
Scooby96's Avatar
 
Join Date: Jun 2003
Posts: 6,086
Likes: 0
Received 0 Likes on 0 Posts
Post

Do keyloggers record a password if you cutr and paste it into the password field?
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
JackClark
Computer & Technology Related
7
17 September 2015 04:23 PM
babber
ScoobyNet General
2
26 June 2001 09:10 PM
Jamie Whitfield
ScoobyNet General
1
30 April 2001 02:23 PM
MartinM
Non Scooby Related
1
13 January 2001 10:44 PM
GranTurismo
ScoobyNet General
9
23 September 2000 01:52 PM



Quick Reply: MSN Hotmail password hacking.



All times are GMT +1. The time now is 07:01 AM.