::Trend Micro Threat Resource Center::

Showing posts with label hotmail. Show all posts
Showing posts with label hotmail. Show all posts

16 July 2011

New Hotmail security features against account hijacking

Microsoft has decided to introduce two new security features for its web-based Hotmail service, in the hope that this will make the accounts more difficult to hijack and eventual hijackings spotted faster.

The first one makes the use of extremely common passwords impossible. "Common passwords are not just 'password' or '123456' (although those are frighteningly common), but also include words or phrases that just happen to be shared by millions of people, like 'ilovecats' or 'gogiants,'" explains Dick Craddock, Program Manager at Microsoft.

The feature will be rolled out soon, and it will hopefully prevent successful brute force “dictionary” attacks.

The second one has already been released, and allows users to report compromised accounts to Microsoft immediately after receiving a spam or scam email from a contact's email account.

This can be done in two ways. Either you move the email in question to the Junk folder and you get offered the option of reporting the possible hack, or you mark it with the "My friend's being hacked!" option:


The feature also works for compromised Gmail and Yahoo! Mail email accounts, and Microsoft relays the information to Yahoo! and Google. In the few weeks since its release, this option has proved to be very helpful.

"When you report that your friend’s account has been compromised, Hotmail takes that report and combines it with the other information from the compromise detection engine to determine if the account in question has in fact been hijacked," says Craddock. "It turns out that the report that comes from you can be one of the strongest 'signals' to the detection engine, since you may be the first to notice the compromise."

The timing for the rollout of these feature could not be better - a recent report says that spammers are gradually shifting distribution from botnets to compromised accounts.

10 October 2009

Webmail phishing attack only the beginning

In the wake of the news reports this week of the large-scale webmail phishing attacks, much of the coverage has surrounded the compromise of email accounts which, according to the numbers, affected a massive amount of webmail users.

However, what has been glossed over is the potential impact on the other aspects of the victims' online lives. The bad guys likely now have more than just access to users' email accounts, they have access to a host of other online services the victim uses.

"A user's unique email address is often used to authenticate a number of web sites, including social networking sites and Instant Messaging on a public IM network," said Paul Wood, MessageLabs Intelligence Senior Analyst, Symantec. "If your email address has been compromised, not only should you change the password there, you should also change it on any other site that uses that email address as a log in ID."

Once the bad guys have email account information and the will to take over a related social networking accounts, all they need to do is try the password reminder links from the login pages. They can then not only use your email to spam, they can also gain access to other personal information stored online.

Over the last year, MessageLabs Intelligence has tracked a number of phishing attacks using Instant Messaging whereby the bad guys collected real IM user account information and passwords and used them to send commercial messages to everyone on the user's buddy list. An invitation to view a funny video or embarrassing pictures by clicking on a link in an IM was the bait and the landing site would then ask the victim to log in with their IM user name and password. For public IM networks, the user name is often the same as the web-based email account.

Phishing isn't the only way the bad guys can gain access to webmail accounts. MessageLabs Intelligence has been aware of an increase in the number of "brute-force" password breaking attempts, where dictionary attacks are used against online webmail accounts to break in, perhaps using POP3 or webmail to conduct the attacks. Users with simple or weak passwords are the most vulnerable. On the website, an attacker will be asked to solve a CAPTCHA puzzle to prove they are a real person. CAPTCHAs can be easily bypassed using a variety of CAPTCHA-breaking tools.

08 October 2009

Statistics of the Hotmail phishing attack

Bogdan Calin from Acunetix examined the passwords published after the Hotmail phishing attack, came to several conclusions and published some basic statistics.

After analysis, we have statistics of the "The top 20 most common passwords" and "Password length distribution" from the list. See here.

07 October 2009

Email Password Leak Swells - Includes GMail, AOL and YahooMail

Yesterday, when reports indicated that the passwords to certain Hotmail accounts had been published, we tried to play it safe by suggesting that all Hotmail users change their passwords.

Now, we're just going to recommend that everybody revisit those settings, as it seems that the passwords to Gmail, Yahoo, and AOL accounts have also been leaked.

The list was posted on the same site - pastebin.com - as the Hotmail-related one. (Although we should note that pastebin.com's owner doesn't appear to be in any way responsible for the spread of the info.)

Also, in case you were wondering, "BBC News has confirmed that many - including Gmail and Hotmail addresses - are genuine."

So be a little overcautious and change the passwords (and security questions/answers) to all of your email addresses.

06 October 2009

10,000 Hotmail Account Passwords Published Online

People with Hotmail accounts - and particularly people with Hotmail accounts beginning with the letter "a" or "b" - should change their passwords as soon as possible. A list containing about 10,000 account names and passwords has been published online.

Apparently the information was posted on pastebin.com on the first of this month. Tom Warren reports that the original post was deleted at some point, but people still managed to view it and spread the data around. So now an unknown number of hackers, scammers, and other bad guys may have the ability to access certain accounts.

What's more, even though the published list only covered email accounts starting with "a" and "b," the fact that everything was in alphabetical order implies that other lists exist. Or the existence of a complete set seems no less likely than the proven existence an incomplete one, at any rate.

So again, change your password if you use Hotmail and haven't done so already. Pick a different security question (and answer), too, while you're at it, and maybe check your outbox for suspicious messages in case your account's been abused.

Microsoft's promised in a statement that it's investigating the problem, so hopefully the source of the account info leak will be identified and plugged, at least.