Page 3 of 3 FirstFirst 123
Results 21 to 28 of 28

Thread: Hotmail Hacking Threat

  1. #21
    Junior Member
    Join Date
    Apr 2003
    Posts
    26

    Red face yes the sending password back method...

    check out the recent flaw fixed some two days ago...

    http://pakiblues.proboards9.com/inde...num=1052475266

    - yes, there's a method to mail someone with the script (vbscript). when the victim opens the HTML based email, it executes the scripts which eventually sends the password back to the attacker. But I feel that one has to store the password on his computer through MSN msger to get hacked that way. Anyway, that has been fixed, but I feel this method can still work.
    - fake login screen were also very popular. attacker just creat a fake login screen somewhere on the net and send the victim an email with the script which can direct the mail page to fake login page asking that 'session expired, login again' type of message and a hotmail look. easy haan?
    - trojans/backdoord and keyloggers are some other possible method but required some social engineering. bind with some other exe and send it to the victim...
    etc etc etc...
    Life would have been alot easier if I had the source code!

  2. #22
    Junior Member
    Join Date
    Nov 2002
    Posts
    1
    Whats the point in hacking hotmail anywasy the risk is 2 high. The amount of gohsts they have on the server is unbeliable, and it verry unlikly that u wont get cought. So whoever is doin it i advise u not 2.

    -Å-Şıľēʼnćęđ-Mŏŋĸ

  3. #23

    uhhh

    no one who "hacks" an hotmail account is hacking the hotmail server. Someones hotmail account could be worthwhile if it was his passport login with his CC info. But no one would have any reason to hack the hotmail server. Who cares about penis enlargment, why would you go after it anyway =p. Its a keylogger, a trojan, a script. Or the person is acting stupid

  4. #24
    er0k
    Guest
    Originally posted here by MsMittens
    Ya. That's one way. Social engineering into convincing a user that they need to send their password or something. Never send passwords via email even if it's the ISP/host asks for it. If it's the host they should have high enough admin access to go in if they truly need to.

    Another way would be using a tool like ettercap, which collects passwords as they travel past on a network.
    yet another thread to where you mention ettercap, why not make a shrine of it in your signature :P

  5. #25
    Has anybody got a password list, or know of a brute forcer that can access acounts for hotmail, will be usefull as a favour for a friend.

    Thanks in advance,

    Robert

  6. #26
    the person could have used a recent flaw on hotmail i am afraid to put the bugtraq link though because i might be banned but i am putting it anyway http://www.securityfocus.com/archive/1/320806

  7. #27
    Junior Member
    Join Date
    Feb 2003
    Posts
    9
    My msn acount has been recently cracked, yesterday to be exact. And is really sucks. Any suggestions on what i can do, does Microsoft care at all?

    accessdenied

  8. #28
    Junior Member
    Join Date
    Jun 2003
    Posts
    10
    when you log into hotmail there is an option telling msn that your on a public computer
    that way it wont send any info to the computer
    [blur]Y R U U [/blur]

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •