Login Register






The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 0 Vote(s) - 0 Average


Why leaks no longer work with Email providers ?!? filter_list
Author
Message
Why leaks no longer work with Email providers ?!? #1
This past two to three years have been the golden age of leaks. A hacker or cracker just need to purchase or download a database, solve the hashed passwords and you have access to the email. As the time goes by a lot of users become aware of this method, which basically is if you can't hack directly the email then use less secure services to obtain a possible password combination.

With the exposure of this underground method people become more aware about re-use the same password across multiple services. The consequences for this are now visible.

1) If you download a database and try to send spam or marketing emails to them, in most cases they will be rejected and a stop sign will show up in the email not delivered message.

2) The biggest email providers now alerts the users when an attempt to gain unauthorized access to the account has happen. This means if anyone tries to login to a "Gmail" "Hotmail" "etc" using a diferent OS, browser, country or ip it will raise a warning sign.

As more and more people know about this the more restrictive rules are set, so, this only means that the good times of email hacking using leaks are over and new methods will have to surface. Nevertheless this doesn't mean that old methods of hacking are obsolute, for example RAT infection will still make it possible to hack a email if the hacker use remote desktop and login to the email using the same system or just setting up the RAT as a proxy in the background and access the email from the proxy.

Nowadays leaks are only good to access other complementary services associated with the email for example cloud storage in case the user uses the same password in diferent services. It will be possible to crack a mega.nz account for example.

We need new methods, until then Happy Hacking!

Reply

RE: Why leaks no longer work with Email providers ?!? #2
(06-04-2018, 12:25 PM)hacxx Wrote: in case the user uses the same password in diferent services. It will be possible to crack a mega.nz account for example.

I can confirm that It's a commonality for users to use the same email/user/password for most, If not all of their online accounts.

During my tests (and believe me It's In the thousands), I've established that around 70-80% of users use the same credentials. Just the other day, after compromising an online shopping entity and obtaining user logins (for that site), I tested them on all major websites and the majority authenticated.
[Image: AD83g1A.png]

Reply

RE: Why leaks no longer work with Email providers ?!? #3
True. If you use the credentials on other sites with less security or that do not notify the user then you can authenticate, the problem is getting access to the emails inbox. In case of Gmail a alert is immediately generated.

I have seen and access hundreds of compromised Mega.nz accounts. The problem is what the owner of that account considers as gold in the outside eyes is garbage. Sure you can access some compromising photos or official documents but why will i collect them. At the end, i just notify them that there account is compromised and should change the password.

In one insulated case the owner though that i was going to blackmail him because of the photos. First he asked for the password to be sure if i was not lying than after i send the password he emailed me back saying "Men you got skills. That was the password for my email a few months ago".

Reply







Users browsing this thread: 1 Guest(s)