Twelve Years of Service
Posts: 8,840
Threads: 567
Points: 6,499NSP
RE: Pwds 05-05-2016, 05:46 PM
#2
Joy. Why aren't companies forcing password changes for users? Or is that not a practical solution?
The Collector is a very apt name huh?
•
Ten Years of Service
Posts: 1,192
Threads: 51
Points: 72NSP
RE: Pwds 05-05-2016, 05:54 PM
#3
I'm not sure if it's considered a breach. I read somewhere about this last night, it seems the guy was crawling leaked usernames/password combinations and adding them to a list. But he may have gotten into something, too. If he hacked all of Yahoo Gmail Mail.ru, and gotten that many email/pass combos out of it, that's pretty awesome actually.
Must have been doing it for a while, too, to have gotten so many of them.
Email: insidious@protonmail.ch
•
Twelve Years of Service
Posts: 72,622
Threads: 307
Points: 50,359NSP
RE: Pwds 05-07-2016, 03:28 PM
#5
This Is a perfect opportunity to social engineer account holders, for example, Gmail.
Simply claim to be a representative of the Email provider advising that their account Is susceptible to being compromised due to the breach, and that they will be receiving a 6 digit verification code to secure It. Then generate a verification code via Gmail's Recovery options (via "text" and not automated call. The SMS message doesn't denote It's purpose, the automated call does) to the account holder's cell phone and request to reply with the code so It's updated on their account.
Of course, once you receive the code, the objective Is to compromise the account. That's provided 2FA Is not enabled and a cell phone number Is added as a Recovery option on the account.
On topic, I'm just wondering the authenticity of the breach. I shall research further.
•
Nine Years of Service
Posts: 272
Threads: 42
Points: 152NSP
RE: Pwds 05-07-2016, 03:49 PM
#8
Seems nothing serious but i say change passwords and such just in case.
kik: ck
Insta: @upset
Twitter: @465
•
Nine Years of Service
Posts: 359
Threads: 23
Points: 166NSP
RE: Pwds 05-07-2016, 08:25 PM
#9
One of our main news websites just confirmed that it's complete bullshit.
GFX Designer
•