Feeds

Hotmail phish exposes most common passwords

Live ID hacking made as easy as 123...

3 Big data security analytics techniques

Data from the Hotmail phishing attack proves that consumer password security remains pants.

The most common single password in the sample of 10,000 purloined Live ID login credentials posted as a text file to developer site PasteBin.com was "123456", something only marginally more secure than the traditional favourite "password".

Neil O'Neil, a digital forensics investigator at secure payments firm The Logic Group, found that "123456" cropped up on the list 64 times. There were 18 uses of the second most popular password, "123456789", in the list.

Although PasteBin's owners had taken down the list the information was still easily retrievable by security researchers, such as O'Neil, and (undoubtedly) hackers who cared to hunt it down.

O'Neil subsequently analysed the list, with the aim of turning the analysis into a presentation on password security for corporate clients.

The list of Live ID login credentials and associated data was posted as a text file to PasteBin. A large number of spelling mistakes in the secondary data (such as email addresses) available alongside the password data points to the source as a phishing attack.

The information bears all the hallmarks of a raw data dump from Hotmail account holders induced to fill out forms on hacker-controlled websites under the guise of a security check or similar.

O'Neil's analysis of the passwords reveals common themes in their makeup. For example, the security researcher noticed that a significant percentage were dates of birth, an inherently weak password. Other passwords spotted in the sample include "ibelongtogod" (Is Real Madrid's Kaka on Hotmail?) and, perhaps by way of cosmic balance, "666666".

Nearly half (42 per cent) of the passwords used only lowercase letters, 19 per cent were purely numeric and only six per cent mixed up alpha-numeric and other characters, according to a separate analysis of the data by web application security firm Acunetix. Many of the top 20 most frequent passwords in the featured given names common in Spanish speaking countries, such as Alejandra and Alberto. This provides circumstantial evidence that the data was harvested at least in part from a Spanish language phishing message.

iloveyou and (the Spanish equivalent) tequiero both appeared in the top 20 list compiled by Acunetix. O'Neil speculates the list might have been posted as part of an online spat between hackers.

Time to change up

Since an estimated two in five users make use of the same password across multiple accounts, the Hotmail password phishing attack gives hackers a head start in attacking more financially sensitive accounts. "People tend to have the same password across many accounts - so there is a good chance that individuals have also compromised the integrity of their eBay or PayPal accounts too," O'Neil commented.

The security researcher reckons it's time to re-evaluate traditional advice on how to choose passwords. "It used to be that the best security advice was to never write down your password," he said. "Today's advice however is to choose complex passwords, write them down and then put them in your wallet.

"You know when your wallet is lost or stolen and therefore that you need to change your passwords. Three initials from your name and postcode will do the trick and will take a hacker weeks to crack. Using an old postcode adds another layer of protection."

News of a second dump of at least 30,000 webmail login credentials also dumped onto PasteBin broke on Tuesday. This list contained apparent password and username details for accounts with a wider range of webmail providers, including Gmail and Yahoo!.

Security researchers are yet to analyse the list, which early indications suggest may involve a greater percentage of abandoned or fake accounts. ®

3 Big data security analytics techniques

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.