Results 1 to 8 of 8

Thread: Hotmail/Yahoo Spam... How?

  1. #1
    Squeeler Vini's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield
    Posts
    1,769
    Thanks
    44
    Thanked
    8 times in 8 posts

    Hotmail/Yahoo Spam... How?

    Last week my girlfriend's Hotmail address book got hit by spammers, her sent items had the messages that were sent which led me to believe her account had been compromised...

    Today, a couple of colleagues have had the same, one with Yahoo, another with Hotmail.

    Is there a hole in the Yahoo/Hotmail platform, or have the accounts been hacked?

    How does this kind of 'spam' work.................... I'm fully aware of spoofing etc (which this is not - is it?), so this one has me stumped.

  2. #2
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Hotmail/Yahoo Spam... How?

    Weak passwords and a brute force attack? Or compromise of a computer used to log in (an internet cafe or wifi spot if the link wasn't encrypted?)
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  3. #3
    Squeeler Vini's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield
    Posts
    1,769
    Thanks
    44
    Thanked
    8 times in 8 posts

    Re: Hotmail/Yahoo Spam... How?

    It feels more "automated" / "bot" driven... Of course, I've had all users change their passwords/questions etc, but it appears to be driven by the receipt of an email...

    IE. the email comes in (remains unread), scours the address book, forwards itself onto the address book...

    (this is all what I'm being told by the user(s) - and appreciate it's possibly not the case but if true, it's a tricky one for my bonce!)

  4. #4
    Banhammer in peace PeterB kalniel's Avatar
    Join Date
    Aug 2005
    Posts
    31,039
    Thanks
    1,880
    Thanked
    3,379 times in 2,716 posts
    • kalniel's system
      • Motherboard:
      • Gigabyte Z390 Aorus Ultra
      • CPU:
      • Intel i9 9900k
      • Memory:
      • 32GB DDR4 3200 CL16
      • Storage:
      • 1TB Samsung 970Evo+ NVMe
      • Graphics card(s):
      • nVidia GTX 1060 6GB
      • PSU:
      • Seasonic 600W
      • Case:
      • Cooler Master HAF 912
      • Operating System:
      • Win 10 Pro x64
      • Monitor(s):
      • Dell S2721DGF
      • Internet:
      • rubbish

    Re: Hotmail/Yahoo Spam... How?

    Credential stealing then automated log in/spamming. Lots of different ways the credentials are stolen - phishing, server/database hacking, other server/website hacked and stolen credentials attempted on common mail companies etc (often via the forgot password functions).

    Most of the major mail companies have been hacked at some point - best to treat the password as essentially throwaway and always use a unique one for the mail client and keep changing it.

  5. #5
    Squeeler Vini's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield
    Posts
    1,769
    Thanks
    44
    Thanked
    8 times in 8 posts

    Re: Hotmail/Yahoo Spam... How?

    Quote Originally Posted by kalniel View Post
    Credential stealing then automated log in/spamming. Lots of different ways the credentials are stolen - phishing, server/database hacking, other server/website hacked and stolen credentials attempted on common mail companies etc.

    Most of the major mail companies have been hacked at some point.
    The above is my take on "how its done" ... but again, the users are adamant they've not been phished, clicked dodgy links and in one case, the email address of one person who's been "hacked" doesn't even give out the information/email address......

    The fact that the spam messages are in the outbox/sent items, to me insinuates someone/something has had access & been in!

  6. #6
    Banhammer in peace PeterB kalniel's Avatar
    Join Date
    Aug 2005
    Posts
    31,039
    Thanks
    1,880
    Thanked
    3,379 times in 2,716 posts
    • kalniel's system
      • Motherboard:
      • Gigabyte Z390 Aorus Ultra
      • CPU:
      • Intel i9 9900k
      • Memory:
      • 32GB DDR4 3200 CL16
      • Storage:
      • 1TB Samsung 970Evo+ NVMe
      • Graphics card(s):
      • nVidia GTX 1060 6GB
      • PSU:
      • Seasonic 600W
      • Case:
      • Cooler Master HAF 912
      • Operating System:
      • Win 10 Pro x64
      • Monitor(s):
      • Dell S2721DGF
      • Internet:
      • rubbish

    Re: Hotmail/Yahoo Spam... How?

    Quote Originally Posted by Vini View Post
    The above is my take on "how its done" ... but again, the users are adamant they've not been phished, clicked dodgy links and in one case, the email address of one person who's been "hacked" doesn't even give out the information/email address......
    That's fine, but doesn't do anything to stop someone hacking the mail server database. But chances are they will have been phished without knowing it. I defy most people to see the difference between a yahoo front end and an exact copy spoof front end or one with an iframe overlay - they STILL don't insist on secure connections.

    http://crave.cnet.co.uk/software/pas...line-49303832/

    And it even happened to me I think - I had an account compromised for an online game and everything stolen - and I'm even someone paranoid enough to run no-script all the time. That or their server was hacked, which they deny.

  7. #7
    Squeeler Vini's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield
    Posts
    1,769
    Thanks
    44
    Thanked
    8 times in 8 posts

    Re: Hotmail/Yahoo Spam... How?

    so again, back to my theory;

    -credentials are "gained" (phished/keylogger/somehow!)
    -credentials go into a nice big bucket with other users credentials which may sit dormant for a while
    -credentials are entered into a nice computer capable of "attempting to access many accounts at once"
    -once in, a 'script' runs and sends this 'spam' to the entire address book
    -process continues

    (obviously in vague-st possible terms!)


    So changing the password & questions, is the best procedure to attempt to combat this....

  8. #8
    Going Retro!!! Ferral's Avatar
    Join Date
    Jul 2003
    Location
    North East
    Posts
    7,860
    Thanks
    561
    Thanked
    1,438 times in 876 posts
    • Ferral's system
      • Motherboard:
      • ASUS Z97-P
      • CPU:
      • Intel i7 4790K Haswell
      • Memory:
      • 12Gb Corsair XMS3 DDR3 1600 Mhz
      • Storage:
      • 120Gb Kingston SSD & 2 Tb Toshiba
      • Graphics card(s):
      • Sapphire Radeon R9 380 Nitro 4Gb
      • PSU:
      • Antec Truepower 750 Watt Modular
      • Case:
      • Fractal Design Focus G Mid Tower
      • Operating System:
      • Windows 10 64 bit
      • Monitor(s):
      • 28" iiyama Prolite 4K
      • Internet:
      • 80Mb BT Fiber

    Re: Hotmail/Yahoo Spam... How?

    I have been getting it for a while now also with my Yahoo account. Bizarre thing for me is that I get job emails continuously sent to me. There is nothing in the sent box but it shows the sender as my email address to myself. Dont know how and why its happening, it just is. Guessing someone has gotten hold of my email address.

    Its really bizarre.

    My GMail account got hacked a few month back from someone in China, shortly after I stopped playing WoW as that also got hacked whilst changing phones and had yet to get the authenticator installed.

    I think the GMail account getting hacked had something to do with an app I downloaded for my Android device. Not 100% sure though.

    My hotmail account has been fine however.

    Recently changed GMail account password and I am going to change my Yahoo one in about 10 mins time to see if I can combat it.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Free Credit Card Radio
    By MagicFreebiesUK in forum Retail Therapy and Bargains
    Replies: 11
    Last Post: 05-09-2005, 10:00 AM
  2. 200,000 posts!
    By DaBeeeenster in forum General Discussion
    Replies: 25
    Last Post: 18-05-2004, 10:00 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •