Zoom7000 Posted October 5, 2009 Posted October 5, 2009 This is not a joke! Change your Hotmail Passwords and Security Questions Immediately! Neowin has received information regarding a possible Windows Live Hotmail "hack" or phishing scheme where password details of thousands of Hotmail accounts have been posted online. An anonymous user posted details of the accounts on October 1 at pastebin.com, a site commonly used by developers to share code snippets. The details have since been removed but Neowin has seen part of the list posted and can confirm the accounts are genuine and most appear to be based in Europe. The list details over 10,000 accounts starting from A through to B, suggesting there could be additional lists. Currently it appears only accounts used to access Microsoft's Windows Live Hotmail have been posted, this includes @hotmail.com, @msn.com and @live.com accounts. Neowin has reported this immediately to Microsoft's Security Response Center and to Microsoft's PR teams in the UK and US and we are currently awaiting feedback on the situation. As this is a breaking story please check back frequently as the story will be updated as soon as more information becomes available. If you are a Windows Live Hotmail user Neowin recommends that you change your password and security question immediately. Thanks to Chris for the news tip Update: According to BBC News, Microsoft is currently "investigating the situation and will take appropriate steps as rapidly as possible." More Information: Thousands of Hotmail passwords leaked online BBC NEWS | Technology | Hotmail accounts 'posted online' Hotmail Password Hacking: Microsoft Investigating Claims Details Of Thousands Of Accounts Put Online | Technology | Sky News
t_h Posted October 5, 2009 Posted October 5, 2009 I was under the impression they were phished rather than hacked but I've changed mine as a precaution anyway.
cookie_monster Posted October 5, 2009 Posted October 5, 2009 Since Hotmail doesn't store passwords as clear text even if they were harvested they wouldn't be much use also if they aren't stored as clear text then they can't be leaked. I suspect it will be a list collected with key loggers or duping users to log into fake hotmail sites or "muppets" who logon to their webmail through proxy anonymizers.
dwhyte85 Posted October 5, 2009 Posted October 5, 2009 Hashes can be cracked... :-) Phished through proxy websites is probably the most likely scenario, I doubt MS has any SQLI on that side of things. Had to send an e-mail out to staff, I think we've had one teacher who has been a victim.
cookie_monster Posted October 5, 2009 Posted October 5, 2009 (edited) Hashes can be cracked... :-) Well yes of course but if it was non reversible encryption it would take some time to crack several million passwords assuming they're good passwords of course It would be nice if hotmail would at least force an annual password change. Edited October 5, 2009 by cookie_monster
OllieC Posted October 5, 2009 Posted October 5, 2009 Can't really be bothered to change live mail password.... :/ Will probably do it later when I've thought of a new password to use.
painejake Posted October 5, 2009 Posted October 5, 2009 Hashes can be cracked... :-) Phished through proxy websites is probably the most likely scenario, I doubt MS has any SQLI on that side of things. Yeah cracking the passwords just wouldn't be worth the amount of time it would take
computer_expert Posted October 5, 2009 Posted October 5, 2009 It would be nice if hotmail would at least force an annual password change. you do have an option to force you to change your password every 70 days or so. it's on the page where you change your password
dwhyte85 Posted October 5, 2009 Posted October 5, 2009 @painejake ... If someone had found a leak it would be TOTALLY worth attempting to crack the hash! In terms of a naughty chappy they could pretty much guarantee a load of access to PayPal accounts, FaceBooks, dim people who save passwords in there mailboxes, potentially several million extra people to spam through address books! ... besides the fact you'd get one over on Microsoft, it would be all over the IT news websites and for any 'hacker' this would be the ultimate exposure!
t_h Posted October 5, 2009 Posted October 5, 2009 If you had the hashes it wouldn't take much "cracking" - more like comparing it to a table of known hashes. Of course this wouldn't work for good passwords but most are atrocious.
cookie_monster Posted October 5, 2009 Posted October 5, 2009 you do have an option to force you to change your password every 70 days or so. it's on the page where you change your password Yes but it's not enabled by default.
CHR1S Posted October 6, 2009 Posted October 6, 2009 I once had my Hotmail hacked, I have no idea how. I had a very random and secure password, never been phished or even used a proxy to access. It was a targetted hack tho as they wanted my old dormant WOW account. Weird.
ICTSM Posted October 6, 2009 Posted October 6, 2009 I've had the same hotmail account for centuries now. I was one of the originals with a common-ish name without any numbers! I always ignore emails from MSN/Hotmail/Live anyway. I had a spurt of password change requests. As a rule, I only view mail that I know the sender of. The rest are deleted/junked.
cookie_monster Posted October 6, 2009 Posted October 6, 2009 As suspected, NOT a hotmail issue. BBC NEWS | Technology | Scam hits more e-mail accounts
IanT Posted October 6, 2009 Posted October 6, 2009 I've just changed my password for my PassPort account............logged into my MSN this morning too find my status name was different!!
ZeroHour Posted October 6, 2009 Posted October 6, 2009 We have been contacted by Microsoft (well someone from a MS Press office) regarding this and they have asked us to post the following info to you in case its needed by anyone. We are aware that some Windows Live Hotmail customers’ credentials were acquired illegally by a phishing scheme and exposed on a website. Upon learning of the issue, we immediately requested that the credentials be removed and launched an investigation. As part of that investigation, we determined that this is not a breach of any Microsoft servers. Subsequently we are taking measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts. If users believe their information was documented on the illegal list, users should fill out the following form to reclaim access to their account. Phishing is an industry-wide problem and Microsoft is committed to helping consumers have a safe, secure and positive online experience. General information on what to do if you believe you have been victimized via a phishing scam is available on this page at our support community. Additional Points Phishing is an industry-wide problem and Microsoft is committed to helping consumers have a safe, secure and positive online experience. Our guidance to customers is to exercise extreme caution when opening unsolicited attachments and links from both known and unknown sources, and that they install and regularly update their anti-virus software. Microsoft recommends customers use the following protective security measures: Renew their passwords for Windows Live IDs every 90 days For administrators, make sure you approve and authenticate only users that you know and can verify credentials As phishing sites can also pose additional threats, install and keep anti-virus software up to date I am glad to see Microsoft trying to get the information out there for people not in the know (like a lot of *staff*) so feel free to pass it on to your staff. You could even mention that MS do free av now at http://www.microsoft.com/security_essentials/ (no MS did not ask me to put this in before asking) and its getting good writeups as far as I have seen and anything is better then AVG free
leon999uk Posted October 6, 2009 Posted October 6, 2009 Scam hits more e-mail accounts More than 20,000 e-mail addresses have been seen by the BBC. The scale of a phishing attack originally thought to be directed at Hotmail may be larger than previously thought. BBC News has seen a list of more than 20,000 more names and passwords that have been posted online. The list contains e-mail addresses and passwords from Hotmail, Yahoo, AOL, Gmail and other service providers. The list was published on the same website as the original list of 10,000 Hotmail login details. Some of the accounts appear to be old, unused or fake. However, BBC News has confirmed that many - including Gmail and Hotmail addresses - are genuine. Other addresses include Comcast and Earthlink accounts. It is not clear whether the list was part of the same phishing attack that collected the Hotmail addresses or a separate scam. Phishing involves using fake websites to lure people into revealing details such as bank account details or login names. A spokesperson for Microsoft said phishing was an "industry-wide problem". Link to full article: BBC NEWS | Technology | Scam hits more e-mail accounts
cookie_monster Posted October 7, 2009 Posted October 7, 2009 Typical The most common single password in the sample of 10,000 purloined Live ID login credentials posted as a text file to developer site PasteBin.com was "123456", something only marginally more secure than the traditional favourite "password". Hotmail phish exposes most common passwords ? The Register
dezt Posted October 7, 2009 Posted October 7, 2009 We have been contacted by Microsoft (well someone from a MS Press office) regarding this and they have asked us to post the following info to you in case its needed by anyone. If users believe their information was documented on the illegal list, users should fill out the following form to reclaim access to their account. Phishing is an industry-wide problem and Microsoft is committed to helping consumers have a safe, secure and positive online experience. General information on what to do if you believe you have been victimized via a phishing scam is available on this page at our support community. This paragraph directs you to a form that starts asking for all sorts of personal information, including your credit card number, expiry date and secret answers to your live accounts. Surely this is not the information Microsoft should be asking for, especially when we are always told to never give out your credit card details when someone asks for them. Am I right in ignoring the form or am I being a bit too over protective of my personal financial information?
cookie_monster Posted October 7, 2009 Posted October 7, 2009 They aren't mandatory fields and I imagine you only fill them in if you use paid for Live services. Mandatory fields are marked (required fields * )
oalcock Posted October 7, 2009 Posted October 7, 2009 I recon this could be a scam, but the domain is the same as hotmail's usual domain. I doubt there would be any reason what so ever why Hotmail would need your card details. :confused:
localzuk Posted October 7, 2009 Posted October 7, 2009 I recon this could be a scam, but the domain is the same as hotmail's usual domain. I doubt there would be any reason what so ever why Hotmail would need your card details. :confused: Did you actually read the message, and the form? ie. the part where the form is for reclaiming accounts you've been locked out of. The subheading saying 'for users with paid services' etc...? It is on an official live.com site, ie. they'd have had to hack the MS website to be able to do that. 1
cookie_monster Posted October 7, 2009 Posted October 7, 2009 As stated above. They aren't mandatory fields and I imagine you only fill them in if you use paid for Live services. Mandatory fields are marked (required fields * )
CHR1S Posted October 7, 2009 Posted October 7, 2009 I recon this could be a scam, but the domain is the same as hotmail's usual domain. I doubt there would be any reason what so ever why Hotmail would need your card details. :confused: Its not a scam, I had to provide that info and more to recover my account before. If its more comfortable you can also ring MS and provide the info over the phone.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now