this is done by accessing aserver that holds the pvt info. If the server is not passsword protected i guess. But i dont know whether it is done from inside or outside. OK i ve heard they could connect to a server and use a exploit to gain access as if the databse is present in their own HDD>