PDA

View Full Version : A Complete Guide to Protecting your Online Accounts


ABhishek
02/21/2006, 20:24
Ok Now this one is going to be big , but it's also gonna be helpful ...
Now I once wrote this papaer for my website which I feel needs to be shared with all of you , since all of you deal with money !!!Though the Programmer crowd in here may be well alware of all these, Maybe this can help the unaware webmasters,
All I'd like to request the SL staff is to make this sticky if you find it helpful
Now, I'll post it in 2 parts , since SL allows only 10k characters long post,

Let's Begin,

If you are a regular Yahoo chatter or visit Hackin based forums or anywhere in general , one Question that you must have definitely come across is "Can you tell me how do I hack yahoo or hotmail or egold?"
It's become a type of joke among frequent visitors of hacker related chat rooms and websites. This article is being written for the sole purpose of defending yourself against such actions.

Let's start by Dispelling a few rumors:

You can use a bruteforcer[one which tried many possibilites of passwords for a particular username] program to get a Yahoo,Hotmail & egold passwords password.
>>My Point>>This simply is not the case. Both Yahoo and Hotmail have security in place specifically designed to stop this kind of attack. Yahoo requires that you enter a random code into an additional field provided as well as the UN and PW after 16 failed login attempts. Failure to enter the correct code will result in a failure to log into the account, even if the Usermame and Passwrods are correct. Hotmail has a different security feature which sends the user to a "lockout" page, which has NO field to enter the Username or Passwords after just one failed attempt.As in egold you are required to enter a turing number which serves em by preventing unlimited signups and/or Cracking/Bruteforcing egold accounts!

There are programs that hack Yahoo, Hotmail and egold.
>>My Point>> Once again, that's not entirely true. While there are programs that claim to be able to hack hotmail, yahoo or egold, all they really seem to be are specialized keyloggers and trojans that send the info from a targets computer. The question is then, if you can get a target to download / run a program, then why would you only steal their email account information? Why not simply take control of the whole thing? A lot of people that use these programs are not well versed enough to know how to cover their tracks and can easily be caught when using such programs. Many of these programs are also specially designed to steal information from the computer that tries to run it,thus exploiting the would-be attacker.

You can email an automated pw recovery service and trick it to gain the pw of the account you choose.

Ever see something that goes something like this:

: : : (([[THIS REALLY WORKS ]])) : : :
(1) send an E-mail to pass.recoverybot@yahoo.com
(2) In the subject box type the screen name of the person whose password you wish to steal
(3) In the message box type the following: /cgi-bin/start?v703&login.USER={your Egold username}&class=supervisor&f={your Egold password}&f=27586&javascript=ACTIVE&rsa
(4) Send the e-mail with priority set to "high" (red in some mail programs)
(5) Wait 2-3 minutes and check your mail
(6) Read the message. Where YOUR password was typed before, NOW, the password of the screen name in the code string is there!!!
Why does this work? It's a special decryption-server that AOL-employees can use to decrypt passwords. The aol backdoor account is a bot that reads your authentification from the message body and identifing you as a valid AOL Staff-member, you will get the password mailed back to you. The trick is that this Bot's script seems to be a little bit buggy and it automatically recognizes you as a supervisor (AOL-Staff member), even if you use a normal AOL account. This means, that EVERYONE having a valid AOL account can hack as many other accounts as he wants.

Well, here's another scam designed to steal your information. This may also explain some of the people saying they were hacked. Obviously, donā't send your password to anyone.

>>My Point>>What it all comes down to is this:
If you're looking to get an email ID, you hack the targets PC, not hotmail ,yahoo or Egold directly. If someone were to actually crack into the hotmail,Yahoo or Egold servers, they would be logged, traced, and the security flaw patched I would say within 15-50 minutes. These types of companies have a multi million or even billion dollar backing, a literal army of first class techs and security teams, and apply the newest SW, HW and intrusion detection/protection methods the industry has to offer.

Now on the other side of the story, you have an end user who probably hasn't even installed SP2 on XP, has all the default settings enabled, doesn't know an .exe file from a .com, uses an un-patched version of IE or AOL or FF, doesn't know how to enable their firewall or configure it if it is enabled, etc.

In other words, why attack a well-trained, well-equip army guarding a document when you can attack a less able individual to get it?

Part 2....below

ABhishek
02/21/2006, 20:28
These are some of the more common methods for "hacking yahoo/hotmail/Egold PWs":

1. fake login page
2. email phishing campaign
3. RAT
4. keyloggers
5. cookie grabber
6. spyware
7. fake programs (rat/kl)
8. physical access to cached PWs
9. Social engineering

At this point I'd like to go over them briefly. You may be expecting me to do a step by step on how to use these methods to exploit someone, but this is not the case in this particular article.
Fake login page:
This method is generally used on public terminals, and can be quite effective for gathering large numbers of Ids. Basically its just a matter of someone making a replication of yahoo hotmail's or egold's login page, by copying and making minor modifications to their source code and setting their page as the home page. They then set the input fields to send the information to an email address or database.For eg: http://egold.somefreehost.com <~~ this url at first site looks like an egold site but be careful it isnt .
SolutionTo avoid falling victim to this, type the address of the page you are logging into directly into the browser. 2) Never even in the worst circumstances should u click on any links that claim to take you directly to PayPal, egold or any other site ... let's take an example below
www.yahoo.com (www.google.com)
Click on it and see what happens ....

Email phishing campaign:
Phishing has unfortunately become a household word, though some people associate it with SPAM. Phishing is really just spamming and using deception and trickery to gain information to exploit a service, system, etc. Phishers have posed as banks, email services, law enforcement agents, online contests, teachers, automated services, Nigerians in need of a way to transfer millions in cash, software firms, friends, acquaintances, even the targets themselves. Anyone and anything that you can impersonate, expect a phisher to try. Their emails generally come with an attachment that contains a program like a trojan, RAT or keylogger or virus that either exploits your system searches for PWs and banking info and sends it to the phisher or simply infects or destroys your PC. Some of these scams can be EXTREMELY well done, and almost indistinguishable from a real email (provided by for example, a company they are impersonating).
Solution -=- Remember, Something that Sounds tooooo Good to be true, then it probably is It's always best to contact the company by phone or mail to confirm anything suspicious.No one would give away millions needlessly ...So use ur common sense!!!

RATs:<Remote Administration tools>
Remote administration tools or remote access tools. These programs allow an attacker varying degrees of control over the PC that has the Software installed. The level of access depends on the RAT. Control over the PC allows installation of other malicious software that can be used to track keystrokes, web sites visited, programs accessed, and even take screenshots of the infected computer and send them to an email address covertly. It is also capable of allowing the attacker to make any changes to the system they would like. Obviously, this isn't good.
Solutions -=- Always Check whatever files u receive , even if the sender is your best friend ..for example exe files that look as if they are Flash files, right click on them and if it read Application then ur at risk .. Most antivirus and spybot removal SW will detect and remove these types of programs. It's also a good idea to not only use, but check the logs, settings, permissions and outgoing/incoming traffic of your firewall to prevent this type of thing from happening to you.Also if you are too eager to see some file sent to you by your mate !!! Check it at www.virustotal.com
Keyloggers:
Keyloggers can track keystrokes, web sites visited, programs accessed, and even take screenshots of the infected computer and send them to an email address covertly. Again, most antivirus and spybot removal SW will detect these. If you fear your pc has been comprimised, you can take steps to ensure your PW isnt logged until you can scan for and remove it.
Solutions -=- Open a word document and write out a list of the Usernames you'll be using and the a list of the PWs. then cut and paste them accordingly into the fields if you fear a KL or other monitoring device may be in use so that while the SW will pick up the keystrokes, it will not know what PWs match the UNs. If you'd like to take that a step farther, write several random letters and numbers around your PW in the word file and cut out the extra letters until you come out with the UN or PW desired.Yet again have a look at the Solution section for RAT's above
Cookie grabber:
This method depends on whether or not the target has opted to save or have the computer remember their Passwords. The information is saved in the cookies and can be used to exploit some mail services. The information can be gained through a website or email containing a script that "grabs" the information.
Solutions -=- Deleting or not allowing the use of cookies can stop this method.

Spyware:
Spyware / adware are small programs installed and executed on a target PC for use as tracking tools generally for advertising purposes. These programs generally rely on web browser vulnerabilities to install and run on your system. However, as previously mentioned, any program that is installed on your PC without your knowledge isn't good. Some attackers have taken this technology and created spybots particularly designed to send sensitive information about your system to a predetermined mail address or database.
Solutions -=- This can generally be avoided by updating and patching your browser as often as possible. I personally suggest using Mozilla Firefox as a browser, as it is not as vulnerable as internet explorer and operates in much the same way, and has a similar interface. There are literally THOUSANDS of anti spyware programs available, two that I find work exceptionlly, especially in conjuction with each other is Spybot Search and Destroy and Adaware SE personal. Before you get a spyware removal program, research it and see what the general concensus is as some programs touted as spyware removers actually install spyware on your system.

Fake programs:
I mentioned this earlier in this article in the dispelling rumors section. There are programs like booters, hotmail and yahoo hackers, point and click trojans, keyloggers, audio and video SW, etc that contain RATs and other malicious programs.
Solutions -=- The obvious way to minimize the chances of becoming a victim of this method of exploitation is not to DL "shady" programs (ie. programs that do illegal things). The general rule is "If something sounds too good to be true, it probably is." When DLing programs, make sure that you have researched them, and the company/website it came from. Keep a record of this as well, and check your system often for signs of exploitation.

Physical access to cached PWs:
This is in my opinion, the easiest way to snag a PW. Having access to a system where the PW has been "saved" or "remembered" means that the PW is located somewhere on the PC. Where depends on the SW, so the location varies depending on what you're looking for. There is also a plethora of legitimate programs designed to find the cached PWs of various programs, and present them, even if they are encrypted.
Solutions -=- Best way to avoid this is to not cache or allow the PC to remember your PWs. You don't give your PW to anyone, why give it to a machine that can't decide on its own whether or not to give it out?

Social engineering:
This can, and often is combined with any of the above methods. Social engineering is really just exploiting people instead of SW. Social engineers use a variety of ways to trick someone into giving them the information they desire. These cons can be amazingly ingenious, professional and complex, or they can be ridiculously crude and almost laughable.
Solutions -=- Again, if you have doubts about the legitamacy of something or someone or something just seems strange don't do it. Don't give out sensitive information, period. You can always check up on a story or website later.So next time your friend asks you for your girl friend's name or your dad's middle name or your exact birthdate from out of nowhere Beware

General Rules:
Think.
Scan often.
Look for potential problems, dont wait for them to find you.
Use case sensitive alphanumeric PWs at least 8 characters long and use symbols like @, #, $ whenever able.

Be aware that these methods are simply the most common. These are not the only way for someone to get your PW. Unfortunatly, if someone wants something bad enough, they're going to get it. At least by familiarizing yourself with these methods, you can recognize scams and potential attempts to steal your information and avoid it.

It is my hope that this article helps you, and screws a slew of lamers and script kiddies into looking for another hobby.

Regards,
Abhishek

ABhishek
02/24/2006, 02:37
NO replies :( :rolleyes:

skiv
03/01/2006, 05:09
100% agree :)
I have all my messengers and the email client and also all the passwords lists on a password-protected removable Flash drive.
If I need a password - I click on an icon which asks me for a main pass and it mounts the passwords virtual disk where I run the password keeper tool, which asks me for the password again and then I can Copy/paste any password I need w/o even clicking Ctrl+C.
After 1 minute of inactivity the virtual disk dismounts automatically.
And so on.

You can think I'm a paranoid?
Yes I am.
Because my passwords mean my money, my business, and my entire life.

Regards, skiv

skiv
03/01/2006, 05:14
PLUS.
Do not invent passwords yourself.
Always generate them, use #$%-_ chars wherever they can be used.
Optimal password length - 12-15 chars.
You wont need to remember them, as you're just copying them from a
protected password keeper tool every time, so they can be even 30 chars long.
The longer the better the password saves your information.

Also keep in mind that anyone can go to your mail server and ask for forgotten password and guess the right answer on the question.
This is a very important backdoor - do not fill there anything like your mothers or your pets name.

Ask one of your friend or maybe your Wife or Husband to try to cheat the "forgotten password" form for your account.

100% agree with ABhishek
Think twice.

Regards, skiv

ABhishek
03/01/2006, 05:37
Yep ur right !!! For people who deal with electronic media our passwords are our money ... so they do mean a lot ...
Great add ons Skiv ...
Abhishek