SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    Internet exploitation using old passwords
Page 1 2 
Go
New
Find
Notify
Tools
Reply
  
Internet exploitation using old passwords Login/Join 
Go Vols!
Picture of Oz_Shadow
posted
This is a new one for me. I'm receiving exploitation emails that say they have recorded me "satisfying myself" via hacked webcam (which I do not have) and as proof, they disclosed one of my old passwords. They of course want money.

The thing is, the password was a correct one that I often used years ago for low security things like internet forum logins.

This led me to checking my email through one of the security sites to see if my email or passwords had been leaked, stolen, hacked etc. Apparently one or two old passwords have been stolen/leaked.

As far as I am aware, Avast is a reputable company, but check on your own.

https://www.avast.com/hackcheck

I entered my email, it sent me an email which had private links to each one they picked up. Clicking it took me to the Avast site that showed the source of each leak or where they discovered it and the option to see the password on the page and cover it again.

Do your own research, but it was a bit of a surprise to see most were old and accurate - some were not any I recognized.
 
Posts: 17944 | Location: SE Michigan | Registered: February 10, 2007Reply With QuoteReport This Post
Thank you
Very little
Picture of HRK
posted Hide Post
sounds to me like they are a buncha wankers...
 
Posts: 24659 | Location: Gunshine State | Registered: November 07, 2008Reply With QuoteReport This Post
Cruising the
Highway to Hell
Picture of 95flhr
posted Hide Post
Just ask them if they would like to buy more pictures similar to what they have. Eek Razz




“Government exists to protect us from each other. Where government has gone beyond its limits is in deciding to protect us from ourselves.”
― Ronald Reagan

Retired old fart
 
Posts: 6547 | Location: Near the Beaverdam in VA | Registered: February 13, 2005Reply With QuoteReport This Post
quarter MOA visionary
Picture of smschulz
posted Hide Post
Yes, I am seeing this too.
Spam phishing emails from foreign countries demanding a bitcoin payment.
The thing is that while they are not specific in the origin they do have some accurate information.
They have an accurate "password" that was used.
Like I said they do not specify the origin but I suspect it was from some hacked online account or forum or whatever.
This can complicate security if you use the same password on every site.
So beware.
Use different passwords.
Use an email address that is not your primary or work address.
Change passwords regularly.
You may want to use an utility such as RoboForm to keep up with.
But don't fall for the fake request!
YMMV
 
Posts: 23408 | Location: Houston, TX | Registered: June 11, 2006Reply With QuoteReport This Post
Page late and a dollar short
posted Hide Post
Same here, the identified one was Linkedin.


-------------------------------------——————
————————--Ignorance is a powerful tool if applied at the right time, even, usually, surpassing knowledge(E.J.Potter, A.K.A. The Michigan Madman)
 
Posts: 8501 | Location: Livingston County Michigan USA | Registered: August 11, 2002Reply With QuoteReport This Post
Wait, what?
Picture of gearhounds
posted Hide Post
Tell them you've already surrendered to the FBI, tell them the computer line is tapped, and that they'll be in touch to collect the evidence. Then hang up the phone.




“Remember to get vaccinated or a vaccinated person might get sick from a virus they got vaccinated against because you’re not vaccinated.” - author unknown
 
Posts: 15985 | Location: Martinsburg WV | Registered: April 02, 2011Reply With QuoteReport This Post
Still finding my way
Picture of Ryanp225
posted Hide Post
Send him the link to this video and tell him it's you pleasuring his mom. (SFW Wink )

Link
 
Posts: 10851 | Registered: January 04, 2009Reply With QuoteReport This Post
No good deed
goes unpunished
Picture of cheesegrits
posted Hide Post
quote:
Originally posted by shovelhead:
Same here, the identified one was Linkedin.

Same here and Linkedin was also the culprit.

I detest Linkedin. I made the mistake of creating an account years ago and had forgotten about it. Roll Eyes
 
Posts: 2702 | Location: The Carolinas | Registered: June 08, 2010Reply With QuoteReport This Post
Member
posted Hide Post
quote:
Originally posted by Oz_Shadow:
I'm receiving exploitation emails that say they have recorded me "satisfying myself" via hacked webcam (which I do not have) and as proof, they disclosed one of my old passwords.

I heard of this scam sometime last year. Supposedly one guy responded back that he had been trying to break into the porn business, and was hoping this hacked video could be used to kick off his career. That's when you'd enjoy seeing the response from the scammers when they open that email.
 
Posts: 8088 | Location: Colorado | Registered: January 26, 2008Reply With QuoteReport This Post
Member
Picture of dsiets
posted Hide Post
I entered my email into the OP's link and it looks like an old PW at a private overseas game server I used(WoW) was hacked.
The exact reason I try to use different PWs for every account. Thanks Keepass.
 
Posts: 7533 | Location: MI | Registered: May 22, 2007Reply With QuoteReport This Post
Fighting the good fight
Picture of RogueJSK
posted Hide Post
quote:
Originally posted by dsiets:
The exact reason I try to use different PWs for every account.


Yep. I've had a few passwords stolen from other forums that were hacked, but it does them no good, because I use a unique password for each site.
 
Posts: 33437 | Location: Northwest Arkansas | Registered: January 06, 2008Reply With QuoteReport This Post
The 2nd guarantees the 1st
Picture of fiasconva
posted Hide Post
Tell them it wasn't you. It was your neighbor and it was shot through his bedroom window. *s*



"Even if the world were perfect it wouldn't be." ... Yogi Berra
 
Posts: 1916 | Location: York County, VA | Registered: August 25, 2007Reply With QuoteReport This Post
Live long
and prosper
Picture of 0-0
posted Hide Post
Have safe computing practices.

Keep one blind, deaf, email free computer for porn research studies.
Keep another for email only and
A third one to use for visual telecommunications.

Thank you for the Avast link. Brought a few 12345678 passwords that i don't remember ever using and one that was close enough to worry me some.

0-0


"OP is a troll" - Flashlightboy, 12/18/20
 
Posts: 12305 | Location: BsAs, Argentina | Registered: February 14, 2003Reply With QuoteReport This Post
Member
Picture of Haveme1or2
posted Hide Post
Humm strange ...
Some are there on one email. The other email has passwords I never have used.

Scary though my oldest email has my old main pass word I used for allot of stuff.
 
Posts: 1002 | Location: Mint Hill NC | Registered: November 26, 2016Reply With QuoteReport This Post
Member
posted Hide Post
Most disturbing to me was an old PW I used on PoliceOne.Com. Figures. Roll Eyes


End of Earth: 2 Miles
Upper Peninsula: 4 Miles
 
Posts: 16553 | Location: Marquette MI | Registered: July 08, 2014Reply With QuoteReport This Post
Member
posted Hide Post
I got the same thing when in Nairobi last week. They wanted ransom in bitcoin. I forwarded the email to the FBI IC3 website.

I changed all my passwords again, the usual. Life goes on.
 
Posts: 6650 | Registered: September 13, 2006Reply With QuoteReport This Post
Member
Picture of RichardC
posted Hide Post
This https://www.avast.com/hackcheck has an odd smell to it. Phishy, even.


It wants you to give them all your email addresses and those of all your friends, family and vendors, etc., so they can check for hacks...

AND, actively monitor those email accounts in the future.

Oh, and here's an offer you can't refuse:

Secure all your accounts with Avast Passwords

Manage your logins with just one unbreakable password, access your accounts with a tap on your phone, and much more.


This is the same company that got in privacy violation trouble with their free CC Cleaner app about a year ago, remember?


https://duckduckgo.com/?q=avas...eaner+privacy&ia=web


____________________



 
Posts: 16312 | Location: Florida | Registered: June 23, 2003Reply With QuoteReport This Post
Member
Picture of jcsabolt2
posted Hide Post
I use third party verification on every account that I possibly can in addition to a stupid long and complex password scheme. For other sites like this one and a few others I stick to a simple password and leave it at that.

For what it was worth, I tried my junk mail account on that AVAST site and it was apparently breached about 3 years ago. Shortly after I started the third party verification and complex password.

If you are looking for personal security software I would stick with McAfee. From what our IT guys have told me Norton is a huge resource hog and I just don't trust these smaller companies. Both McAfee and Norton are the only two any of my employers have ever used, government or private employers.


----------
“Nobody can ever take your integrity away from you. Only you can give up your integrity.” H. Norman Schwarzkopf
 
Posts: 3664 | Registered: July 06, 2006Reply With QuoteReport This Post
Go Vols!
Picture of Oz_Shadow
posted Hide Post
quote:
Originally posted by RichardC:
This https://www.avast.com/hackcheck has an odd smell to it. Phishy, even.


It wants you to give them all your email addresses and those of all your friends, family and vendors, etc., so they can check for hacks...

AND, actively monitor those email accounts in the future.



I wasn’t promoting their services. The verification part required nothing more than an email. As a security company what better way to sell than to prove clients private info has been exposed and is being traded around the web.

For me, I audited my extensive PW list. I, like others, use many of them, but I did find a couple older ones that still used the compromised credentials.

Personally, my security change will be coming up with a variety of new passwords and changing them all each time I use them next.
 
Posts: 17944 | Location: SE Michigan | Registered: February 10, 2007Reply With QuoteReport This Post
Member
Picture of downtownv
posted Hide Post
Thanks for posting this
DropBox Adobe AOL were all breached.
I change those passwords.
It was easy,
I passed it on to others in my contacts.


_________________________
 
Posts: 8945 | Location: 18 miles long, 6 Miles at Sea | Registered: January 22, 2012Reply With QuoteReport This Post
  Powered by Social Strata Page 1 2  
 

SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    Internet exploitation using old passwords

© SIGforum 2024