Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 32 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Other
Password reset beware
EH-Net
May 23, 2013, 01:38:53 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
Password reset beware
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Password reset beware (Read 12562 times)
0 Members and 1 Guest are viewing this topic.
sgt_mjc
Sr. Member
Offline
Posts: 294
Password reset beware
«
on:
September 05, 2008, 11:49:18 AM »
I came across this on Yahoo. I thought I would share with the rest of you.
http://tech.yahoo.com/blogs/null/104079
The scary thing is, that I'm hard pressed to think of a better way to reset a lost password. Any ideas?
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: Password reset beware
«
Reply #1 on:
September 05, 2008, 12:24:21 PM »
Good read and it's true too. With all these useful reconnaissance tools out today like Maltego, all attackers have to do now days is do some information gathering then own your e-mail accounts. This definitely sounds like the way I'd go depending on the computer literacy of the user I'd be attacking. Of course there's always other ways of getting passwords like phishing, but if a user knows their shit on creating passwords this is the thing to do. Personally besides Maltego, I've found target MySpace Accounts that hold juicy personal information about the target and if people were to get there hands on it could be useful for going the 'Forgot My Password' route. Of course when going this way, Social Engineering will be useful too.
Logged
eCPPT, GCIH, OSCP, OSWP
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: Password reset beware
«
Reply #2 on:
September 05, 2008, 12:32:08 PM »
I don't think we'll be able to get away from it anytime soon, but there are some things that can be done to make it safer.
On some of the sites I use, the site sends an email with a unique URL to the address that I registered with. After clicking the link, I still have to enter some personal information. This isn't perfect--someone could have already compromised my email--but it's better than letting me reset the password entirely in-band.
Sites also need to log IP addresses when a reset is requested and monitor post-reset activity. If your banking password is reset, the bank should not allow your account to transfer all of your money to another account or allow a transaction that is 10x normal without actually calling you to make sure everything is okay.
One thing I do to protect myself is to use information that is not true, but that I can remember. You can't get the answers to my questions by going to my MySpace page.
Logged
BS in IT, CISSP, MS in IS Management (in progress)
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: Password reset beware
«
Reply #3 on:
September 05, 2008, 12:40:47 PM »
I see what you mean with the bank and using information when registering that is false but can be remembered by you, and highly agree. I'm just saying in the past, I've been able to retrieve the birthday, zip code, and the answer to peoples secret question, but then again they weren't exactly into security and even stated the high schools they attended, etc.
Logged
eCPPT, GCIH, OSCP, OSWP
sgt_mjc
Sr. Member
Offline
Posts: 294
Re: Password reset beware
«
Reply #4 on:
September 05, 2008, 01:11:15 PM »
Kris,
Your post just goes to show where the weakest link still is. Even with the recon tools and social engineering, compromising an account wouldn't be possible without the user.
Unicityd,
I do the same things with my secret questions. As for the banks doing what you suggest, do you trust them? I'm sure that they are reasonable secure, but how far do you really trust them? The way current law is around here, is that they must take reasonable precautions. As a security guy, I push for as tight a control as possible while that is not always financially feasible.
Thanks for the input guys.
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
Kev
Sr. Member
Offline
Posts: 428
Re: Password reset beware
«
Reply #5 on:
September 05, 2008, 01:35:56 PM »
This is one of the oldest "hacks" around for personal email. I have used it myself on occasions when I was asked to test the security of personal emails. I usually recommend false data to be used for your password reset.
«
Last Edit: September 05, 2008, 01:37:27 PM by Kev
»
Logged
dalepearson
Sr. Member
Offline
Posts: 357
Re: Password reset beware
«
Reply #6 on:
September 05, 2008, 02:37:50 PM »
I was discussing this very thing with someone in the office only on Tuesday this week.
Its a mad world we live in.
Logged
:: Subliminal Hacking ::
/
:: Security Active Blog ::
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: Password reset beware
«
Reply #7 on:
September 05, 2008, 04:05:27 PM »
Quote from: sgt_mjc on September 05, 2008, 01:11:15 PM
As for the banks doing what you suggest, do you trust them?
I don't trust them, but my dog keeps digging up the mason jars I buried. What can you do?
Logged
BS in IT, CISSP, MS in IS Management (in progress)
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Password reset beware
«
Reply #8 on:
September 06, 2008, 03:34:04 AM »
Not directly related to password resets, but is still in the realm of how organisations (banks in this case) use insecure information to validate indentity.
I called bank X to discuss my account, first I had to enter account number via touch tone phone (don't know how secure this is, my guess is I don't want to know either...), then I had to enter my 'security PIN' which is automatically set to date of birth in 6 figures (no way of changing). When I finally got through to a human I was asked two 'random security questions': How old I'll be at my next birthday (see PIN), and what day of the week my last birthday was (again, see PIN).
I
could only answer the last one because I called 2 weeks after my birthday.
Whilst I think all this is poor I'm stuck in the same boat as sgt_mjc, I can't think of a better way.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
shakuni
Jr. Member
Offline
Posts: 80
Re: Password reset beware
«
Reply #9 on:
September 17, 2008, 12:06:25 AM »
I tried resetting password of some random people that I found on google. And I have about 25% success rate(although I didn't actually reset their passwords, I just went upto the password reset page after answering the secret question and closed it).
Scary, isn't it?
Logged
There is no rule, law or tradition that apply universally... including this one.
apollo
Full Member
Offline
Posts: 146
Re: Password reset beware
«
Reply #10 on:
September 17, 2008, 06:31:27 PM »
I think that mutli-factor authentication is going to eventually be the key to this. It will end up being a pain, but until we come up with something better than passwords, it will probably be better than what we have. I know that paypal and some of the others already have one-time-password generator fobs which you can use along with your username and pin in order to login. That still doesnt' solve the forgot my pin problem, but even if they can reset your pin, they still have to social engineer you into providing your otp. I figure eventually you'll lick the screen and it will test your DNA to let you in or something but I think I'd still rather use the OTP generator than log-in in the library when that happens.
Logged
CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+
LSOChris
Guest
Re: Password reset beware
«
Reply #11 on:
September 17, 2008, 11:10:57 PM »
Quote from: apollo on September 17, 2008, 06:31:27 PM
I think that mutli-factor authentication is going to eventually be the key to this. It will end up being a pain, but until we come up with something better than passwords, it will probably be better than what we have. I know that paypal and some of the others already have one-time-password generator fobs which you can use along with your username and pin in order to login. That still doesnt' solve the forgot my pin problem...
I agree that some sort of multifactor is the fix, at least for the short term.
the problem is how do you pay for all those keyfobs, business have money to do that or have a vested interest is protecting its customers from harm especially when that harm usually means losing business so they may give them to their users.
free email services make money from advertising, i doubt yahoo will be handing out keyfobs and i doubt the majority of yahoo's free email service users will be shelling out the money for them either. so what are we to do?
Logged
sgt_mjc
Sr. Member
Offline
Posts: 294
Re: Password reset beware
«
Reply #12 on:
September 19, 2008, 02:25:29 PM »
I know that I'm no fan of paying for a service like email. I get an account with my ISP, but I'm not expecting a keyfob anytime soon. As for my yahoo account, I use it for all of the stuff I want to have around for a while. That is the one thing I don't like about my ISP account, if I change service, I loose it.
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
Kev
Sr. Member
Offline
Posts: 428
Re: Password reset beware
«
Reply #13 on:
September 20, 2008, 09:16:29 AM »
As far as free email accounts are concerned, If you follow good password rules along with false password reset information you will be fine in most cases. Your main concern then will be keyloggers. Never check your email from a public computer, say for instance like one in a hotel lobby Someone I know just did and there was a keylogger installed that captured his email password which in turn allowed whoever it was to transfer a large amount of money from his Etrade account. Your second concern would be checking your email from a free wifi hotspots where you might encounter fake login pages or session captures. Session captures with tools like ferret, etc...work ok in lab situations but are tricky to do in the real world, at least in my experience and are still rare so I am not as worried about those at this time. However I am sure in time it will improve and become more popular. I guess if we really want to get paranoid, we can worry about sniffers being placed at the ISP , which is not a bad reason to to encrypt actually.
I am sure everyone has read this about Sarah Palin on the Errata security site:
The "hacker" saw the e-mail address "
gov.sarah@yahoo.com
" appear in a Washington Post story about the Governor. He tried the password recovery tool and found the question. He googled for information about the answer. After a few tries like "high school" he finally got the right one, "Wasilla high".
If you feel inclined to use a free email service, use Gmail. For instance while Yahoo will give up your secret question to anybody who asks for it, Gmail will only give out your secret question after 5 days of inactivity on the account. Not a huge security advantage but still little things can add up to frustrate some attackers.
«
Last Edit: September 20, 2008, 11:12:03 AM by Kev
»
Logged
setec78
Guest
Re: Password reset beware
«
Reply #14 on:
September 23, 2008, 10:03:39 PM »
One thing that I discovered by mistake was that after I read about the Palin hack, I tried to see how easy it was to hack my yahoo account. I got halfway through but couldn't remember my secret question, and realized it was a custom question that I made years ago, so I sent a request to Yahoo to reset it and change the new question.
Anyway, I got an email back from Yahoo stating I need to follow a link to setup a new question. Well, I never followed through with it, but I still have the link. So, I went back to reset my password (without following the link first) and interesting to note it gave me an error stating: Sorry, your password can't be reset online
So if a hacker were to try to reset my account they would be greeted with this dead end. I am planning on changing the question sometime in the future but for now it's actually pretty safe because the reset option is sorta in limbo so to speak.
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Editor-In-Chief
: Special Xmas Deal: 10% Off eLearnSecurity Courses
(3) by
hekvvddtest
Greetings
: Hello
(6) by
hekvvddtest
Greetings
: Obtain The Scoop On mulberry bags Before You Are Too Late
(13) by
hekvvddtest
Calendar Of Events
: HITBSecConf2013 – Amsterdam
(9) by
hekvvddtest
Special Events
: [Article]-Webcast: Deep Dive into Red Teaming with the Metasploit Framework
(19) by
hekvvddtest
Network Pen Testing
: HackaServer - Anyone tried it?
(4) by
hekvvddtest
Greetings
: Good day ...
(7) by
hekvvddtest
Gates
: Chris Gates' Blog RSA Finalist
(5) by
hekvvddtest
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(1) by
hekvvddtest
General Certification
: nth topic on Career Advice
(9) by
hekvvddtest
General Certification
: Direction
(5) by
hekvvddtest
Hardware
: Discreet Hacking Devices
(8) by
hekvvddtest
Calendar Of Events
: CanSecWest 2013
(5) by
hekvvddtest
Forensics
: Burn Note
(5) by
hekvvddtest
Calendar Of Events
: Cyber Readiness Challenge - Rome
(1) by
hekvvddtest
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.