Computer Hope

Other => Computer News => Topic started by: Zylstra on September 21, 2008, 08:51:51 PM

Title: Sarah Palins Email... the "Hacker's" Interview
Post by: Zylstra on September 21, 2008, 08:51:51 PM
http://itmanagement.earthweb.com/secu/article.php/3772981/The+Security+Lesson+in+the+Sarah+Palin+Email+Hack.htm

Sarah Palins email was recently hacked, as many of you know. She took the poor choice of using an @yahoo.com email address, meaning that there was a wonderful Password Recovery feature.
Details about how this feature was abused:
Quote
As it turns out, I was right. Here’s how the alleged hacker claims to have accessed the account (sic):

“…after the password recovery was reenabled, it took seriously 45 mins on wikipedia and google to find the info, Birthday? 15 seconds on wikipedia, zip code? well she had always been from wasilla, and it only has 2 zip codes (thanks online postal service!)

the second was somewhat harder, the question was “where did you meet your spouse?” did some research, and apparently she had eloped with mister palin after college, if youll look on some of the screen[shots] that I took and other fellow anon have so graciously put on photobucket you will see the google search for “palin eloped” or some such in one of the tabs.

I found out later though more research that they met at high school, so I did variations of that, high, high school, eventually hit on “Wasilla high” I promptly changed the password to popcorn and took a cold shower…"
Read more:
http://itmanagement.earthweb.com/secu/article.php/3772981/The+Security+Lesson+in+the+Sarah+Palin+Email+Hack.htm

Another story:
http://blog.wired.com/27bstroke6/2008/09/palin-e-mail-ha.html ( << A direct quote by the "hacker" contains a language obscenity)

Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: kpac on September 22, 2008, 03:01:27 PM
Hadn't heard it actually. Nice story. :D
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: drmsucks on September 22, 2008, 05:53:16 PM
Why anyone would provide correct info to the "forgot your password" questions escapes me. The answers to all those questions are PASSWORDS and need to be treated as such.

If the answer to "Where'd you meet your husband" had been: -Pr$>68b&zhQ2)}52F, I don't think they would have gotten in.
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: soybean on September 24, 2008, 09:50:31 AM
Quote
I found out later though more research that they met at high school, so I did variations of that, high, high school, eventually hit on “Wasilla high” I promptly changed the password to popcorn and took a cold shower…"
ROTFL
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: mcxeb52! on September 24, 2008, 10:05:12 AM
I wonder what Palin's face looked like when she couldn't access her own account on first go  ;D
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: evilfantasy on September 25, 2008, 01:28:23 AM
The question I have is where is the mention of the alternate email you need to retrieve the account information?

I said in another thread that since it's Yahoo I wouldn't doubt if the information was sold rather than hacked. It doesn't add up for me.

Quote
Like most web account services, Yahoo Mail provides an option to reset or recover one's user name and password. What is unclear is how the account recovery was rerouted from the alternative email address chosen by Palin to a secondary email address.

Palin's email account hacked via social engineering (http://news.zdnet.co.uk/security/0,1000000189,39490068,00.htm)

Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: drmsucks on September 25, 2008, 11:13:44 AM
I said in another thread that since it's Yahoo I wouldn't doubt if the information was sold rather than hacked. It doesn't add up for me.

Do you mean that you think that someone at Yahoo broke in to the account and sold the info?
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: evilfantasy on September 25, 2008, 11:31:43 AM
Yep. It's happened with Yahoo before in selling email addresses to spammers.

I have one Yahoo email that I have never used to sign up for anything. It collects spam daily.
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: drmsucks on September 25, 2008, 11:58:15 AM
Interesting...
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: BC_Programmer on September 25, 2008, 11:59:21 AM
Selling E-Mail Addresses is One thing, selling their passwords is another.
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: evilfantasy on September 25, 2008, 12:06:30 PM
True, but what I'm not getting is there is no mention of the alternate email address that is required to retrieve account info.

Just doesn't add up for me...
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: drmsucks on September 25, 2008, 12:32:01 PM
By "alternate email address," do you mean an address to send the password to - after answering the recovery questions?
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: evilfantasy on September 25, 2008, 12:37:30 PM
Yep. You need one to finish the security questions when registering a new account.
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: Siscorskiy on September 25, 2008, 05:20:01 PM
PWNED....
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: kpac on September 27, 2008, 02:45:40 AM
PWNED....

Hmmm?
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: Siscorskiy on September 27, 2008, 04:11:39 PM
She shouldnt have made the recovery questions "the real stuff"

 ;D
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: mcxeb52! on September 28, 2008, 02:36:03 PM
it's a second password! Case Closed! ;D
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: Dead_reckon on September 29, 2008, 01:15:03 PM
Yeah, I agree. I think her account was sold off. Sad world this is.
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: parker90 on September 30, 2008, 08:33:44 AM
shes only got herself to blame.
 ;)
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: mcxeb52! on September 30, 2008, 06:37:23 PM
shes only got herself to blame.
 ;)

she must be glad that her email isn't important to the world. At least the email in the yahoo address that got hacked!
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: !~*:.Pink Floyd.:*~! on September 30, 2008, 07:24:19 PM
Shes a political candidate For Crying out loud.

you think Palin might have a personal Adviser that checks emails for her and notice how easy it is to get into her account.
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: patio on October 01, 2008, 06:55:53 AM
shes only got herself to blame.
 ;)

So this makes it OK to do what they did ? ?
That's a twisted line of reasoning...
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: squall_01 on October 01, 2008, 10:30:18 AM
no but the thing is you need to make them secure I dont use any of that just something close an a character from my one game. 
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: mcxeb52! on October 01, 2008, 07:26:29 PM
Not ok to be a hacker and hacking but also not ok to make things hack easy ;D
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: BC_Programmer on October 01, 2008, 07:39:00 PM
not hacker ROXOR 712 15 sqr(12) 67 lulz mcgyver bullet straw!
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: squall_01 on October 03, 2008, 08:58:22 AM
You want your password to be impossible to understand.
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: mcxeb52! on October 03, 2008, 10:44:31 AM
You want your password to be impossible to understand.

who cares about understanding it? I just need to know it;D

Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: squall_01 on October 03, 2008, 10:46:47 AM
thats what I'm saing like useing you birthday would be bad. oh crap have to change mine  :P
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: kpac on October 03, 2008, 01:10:58 PM
thats what I'm saing like useing you birthday would be bad. oh crap have to change mine  :P

Yes, but does anyone on here (besides yourself) know your birthday?
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: patio on October 03, 2008, 07:30:25 PM
yep...
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: patio on October 03, 2008, 07:35:21 PM
September 22nd 1988...
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: typhoeus on October 04, 2008, 01:28:24 PM
Right, well let's hack him then.  Quick, before he changes his password.


Yes, but does anyone on here (besides yourself) know your birthday?

Doesn't your name appear in bold on the birthday list on the main page if that exact day is your birthday?
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: kpac on October 04, 2008, 01:35:31 PM
Doesn't your name appear in bold on the birthday list on the main page if that exact day is your birthday?

Oh yea....
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: mcxeb52! on October 05, 2008, 09:39:53 PM
John MCCain: i am john mccain. i am now 72 years old and hoping that sarah learns enough to take over the presidency because i won't live too much longer.
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: squall_01 on October 06, 2008, 10:24:51 AM
thats the truth but I can still have it differnt ways then that theres like 20 possible ways if that was my password an all so if you recall the one post it some what mentioned it.
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: patio on October 06, 2008, 05:34:34 PM
Once again squall you've illustrated it nicely...
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: squall_01 on October 07, 2008, 06:57:02 AM
I did??????????????????
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: evilfantasy on October 08, 2008, 12:35:59 PM
I wonder how he feels now. Do they serve popcorn in jail?

Palin hacker indicted http://www.thesmokinggun.com/archive/years/2008/1008081palin1.html

Quote
A federal grand jury has indicted the son of a Democratic Tennessee state lawmaker for allegedly hacking into Sarah Palin's e-mail account.

A 20-year-old named David Kernell, f Knoxville, Tenn., the son of state Rep. Mike Kernell, was indicted yesterday by a federal grand jury for intentionally accessing without authorization the e-mail account of the vice presidential candidate.

Kernell, an economics major at the University of Tennessee, faces a maximum of five years in prison, a $250,000 fine and a three-year term of supervised release.
http://www.theglobeandmail.com/servlet/story/RTGAM.20081008.WBwbStumped082120081008102621/WBStory/WBwbStumped0821

Oh, and I think the word "hacker" is a bit over used here.
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: typhoeus on October 08, 2008, 01:46:16 PM
Oh, and I think the word "hacker" is a bit over used here.

Good point.

I wonder how he feels now. Do they serve popcorn in jail?

With the Friday night movies.
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: Zylstra on October 08, 2008, 02:35:05 PM
Well, the definition of Hacker fits...
But, still...
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: street1 (RIP) on October 09, 2008, 05:11:57 AM
I am from Georgia and would like to know,was he a hacker,or cracker? :D
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: fireballs on October 09, 2008, 05:21:09 AM
I agree with street he's a cracker. Hackers are best konwn for writing programs ('hacking' them down to fit on older HDD) what this guy did was social engineering with abit of common sense, if his story is to be believed.

FB
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: street1 (RIP) on October 09, 2008, 05:33:39 AM
I thought so fireballs,my son writes software for ProLogic
and he is a hacker.Only way to fix problems that have gone
 noisey flat... :-X

Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: kpac on October 09, 2008, 02:15:22 PM
Definitions: ;D
Hacker (http://www.google.ie/url?sa=t&source=web&ct=res&cd=1&url=http%3A%2F%2Fsearchsecurity.techtarget.com%2FsDefinition%2F0%2C%2Csid14_gci212220%2C00.html&ei=-mXuSOmDBYHm1gbyx9y9Bw&usg=AFQjCNE7UkR-6vbBZAwxaIo-llxWOS_Cfg&sig2=dLfvrp3Ku_WKbw_BuRnNaQ)
Cracler (http://www.google.ie/url?sa=t&source=web&ct=res&cd=1&url=http%3A%2F%2Fnetforbeginners.about.com%2Fod%2Fc%2Fg%2Fdef_cracker.htm&ei=LGbuSI6FGIiy1gbQpbCoBw&usg=AFQjCNFLsYAWSpFPFCQVAkU9esIfIp7cjw&sig2=jx7_I_1PtguLw3Kgzvzb-g)

 ::) ;D
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: Zylstra on October 09, 2008, 07:44:09 PM
Google Query: "Define: Hacker"

Definitions of hacker on the Web:

    * The term used to refer to someone skilled in the use of computer systems, especially if that skill was obtained in an exploratory way. ...
      www.contentverification.com/glossary/f-j.html

    * Originally used to describe a computer enthusiast who pushed a system to its highest performance through clever programming.
      www.smartbizconnection.com/advertising_glossary_index.htm

    * The dictionary defines "hacker" as a slang term describing a person who carries out or manages something successful. A hacker is someone who spends many hours with the computer often successfully operating it by trial and error without first referring to the manual. ...
      www.fas.org/irp/congress/1996_hr/s960605a.htm

    * This is someone who enjoys exploring and learning about computer systems. It is often confused with cracker, which is a person who has a mischievous attitude and often attempts to break into computer systems.
      www.broadband-guide.org.uk/jargon-buster.html

    * A person that accesses electronic information without permission in order to cause harm by creating a virus or worm.
      www.masd.k12.pa.us/facility/teachweb/sverdecchia/compterm.htm
Title: Re: Sarah Palins Email... the "Hacker's" Interview
Post by: evilfantasy on October 09, 2008, 07:54:11 PM
Social engineering

Quote
All social engineering techniques are based on specific attributes of human decision-making known as cognitive biases.[2] These biases, sometimes called "bugs in the human hardware," are exploited in various combinations to create criminal attack techniques, some of which are listed here:
http://en.wikipedia.org/wiki/Social_engineering_(security)