Archive for March 9th, 2010

Hotmail Password Phishing Update: "all Your Credentials Are Belong To Us"

By Jerry J. Jansen On March 9, 2010 No Comments

A new wave of details and even more questions related to the disclosure of Hotmail, MSN, and Live! credentials were recently revealed by Neowin.com. The BBC reported on another 20,000 credentials posted on pastebin.com. They also disclosed that Google found a third list of credentials of undisclosed size.

The credentials were not limited to Microsoft services; they also included Yahoo!, Gmail, AOL, Comcast, and Earthlink. The breadth and scope of this is intriguing as Microsoft and Google both have made statements insisting it is the result of phishing.

I am not willing to say it is not phishing, or related to phishing; however, it could be a combination of attacks leading to this large quantity of compromised accounts. Many trojans and other malware capture and upload any credentials cached by Internet Explorer and Firefox.

I recently mentioned the chance this was related to a MSN Messenger friends block verification scam that was popular at the end of August and beginning of September. Earlier, SophosLabs reported on a similar scam targeting Microsoft passwords. This alone implies that if it is only phishing, multiple tactics were taken.

Many users have expressed concern to me today regarding the difficulty

Click here to continue reading


  • Blog Sponsors

  • Advertise on this active blog for only $27.00/mo. Send us an email for more information.

  • Archives

    July 2010
    S M T W T F S
    « Jun «-»  
     123
    45678910
    11121314151617
    18192021222324
    25262728293031
  • Categories

  • MY WEBSITES

  • Login / RSS

  •  

Load time improved by PHP Speedy Load time improved by PHP Speedy