Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Sarah Palins Email... the "Hacker's" Interview  (Read 28258 times)

0 Members and 1 Guest are viewing this topic.

Zylstra

    Topic Starter
  • Moderator


  • Hacker

  • The Techinator!
  • Thanked: 45
    • Yes
    • Technology News and Information
  • Certifications: List
  • Computer: Specs
  • Experience: Guru
  • OS: Windows 7
Sarah Palins Email... the "Hacker's" Interview
« on: September 21, 2008, 08:51:51 PM »
http://itmanagement.earthweb.com/secu/article.php/3772981/The+Security+Lesson+in+the+Sarah+Palin+Email+Hack.htm

Sarah Palins email was recently hacked, as many of you know. She took the poor choice of using an @yahoo.com email address, meaning that there was a wonderful Password Recovery feature.
Details about how this feature was abused:
Quote
As it turns out, I was right. Here’s how the alleged hacker claims to have accessed the account (sic):

“…after the password recovery was reenabled, it took seriously 45 mins on wikipedia and google to find the info, Birthday? 15 seconds on wikipedia, zip code? well she had always been from wasilla, and it only has 2 zip codes (thanks online postal service!)

the second was somewhat harder, the question was “where did you meet your spouse?” did some research, and apparently she had eloped with mister palin after college, if youll look on some of the screen[shots] that I took and other fellow anon have so graciously put on photobucket you will see the google search for “palin eloped” or some such in one of the tabs.

I found out later though more research that they met at high school, so I did variations of that, high, high school, eventually hit on “Wasilla high” I promptly changed the password to popcorn and took a cold shower…"
Read more:
http://itmanagement.earthweb.com/secu/article.php/3772981/The+Security+Lesson+in+the+Sarah+Palin+Email+Hack.htm

Another story:
http://blog.wired.com/27bstroke6/2008/09/palin-e-mail-ha.html ( << A direct quote by the "hacker" contains a language obscenity)


kpac

  • Web moderator


  • Hacker

  • kpac®
  • Thanked: 184
    • Yes
    • Yes
    • Yes
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 7
Re: Sarah Palins Email... the "Hacker's" Interview
« Reply #1 on: September 22, 2008, 03:01:27 PM »
Hadn't heard it actually. Nice story. :D

drmsucks



    Specialist

    Re: Sarah Palins Email... the "Hacker's" Interview
    « Reply #2 on: September 22, 2008, 05:53:16 PM »
    Why anyone would provide correct info to the "forgot your password" questions escapes me. The answers to all those questions are PASSWORDS and need to be treated as such.

    If the answer to "Where'd you meet your husband" had been: -Pr$>68b&zhQ2)}52F, I don't think they would have gotten in.
    If you don't have time to do it right
                    ...when will you have time to do it over?

    soybean



      Genius
    • The first soybean ever to learn the computer.
    • Thanked: 469
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 10
    Re: Sarah Palins Email... the "Hacker's" Interview
    « Reply #3 on: September 24, 2008, 09:50:31 AM »
    Quote
    I found out later though more research that they met at high school, so I did variations of that, high, high school, eventually hit on “Wasilla high” I promptly changed the password to popcorn and took a cold shower…"
    ROTFL

    mcxeb52!

    • Guest
    Re: Sarah Palins Email... the "Hacker's" Interview
    « Reply #4 on: September 24, 2008, 10:05:12 AM »
    I wonder what Palin's face looked like when she couldn't access her own account on first go  ;D

    evilfantasy

    • Malware Removal Specialist


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Sarah Palins Email... the "Hacker's" Interview
    « Reply #5 on: September 25, 2008, 01:28:23 AM »
    The question I have is where is the mention of the alternate email you need to retrieve the account information?

    I said in another thread that since it's Yahoo I wouldn't doubt if the information was sold rather than hacked. It doesn't add up for me.

    Quote
    Like most web account services, Yahoo Mail provides an option to reset or recover one's user name and password. What is unclear is how the account recovery was rerouted from the alternative email address chosen by Palin to a secondary email address.

    Palin's email account hacked via social engineering


    drmsucks



      Specialist

      Re: Sarah Palins Email... the "Hacker's" Interview
      « Reply #6 on: September 25, 2008, 11:13:44 AM »
      I said in another thread that since it's Yahoo I wouldn't doubt if the information was sold rather than hacked. It doesn't add up for me.

      Do you mean that you think that someone at Yahoo broke in to the account and sold the info?
      If you don't have time to do it right
                      ...when will you have time to do it over?

      evilfantasy

      • Malware Removal Specialist


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Sarah Palins Email... the "Hacker's" Interview
      « Reply #7 on: September 25, 2008, 11:31:43 AM »
      Yep. It's happened with Yahoo before in selling email addresses to spammers.

      I have one Yahoo email that I have never used to sign up for anything. It collects spam daily.

      drmsucks



        Specialist

        Re: Sarah Palins Email... the "Hacker's" Interview
        « Reply #8 on: September 25, 2008, 11:58:15 AM »
        Interesting...
        If you don't have time to do it right
                        ...when will you have time to do it over?

        BC_Programmer


          Mastermind
        • Typing is no substitute for thinking.
        • Thanked: 1140
          • Yes
          • Yes
          • BC-Programming.com
        • Certifications: List
        • Computer: Specs
        • Experience: Beginner
        • OS: Windows 11
        Re: Sarah Palins Email... the "Hacker's" Interview
        « Reply #9 on: September 25, 2008, 11:59:21 AM »
        Selling E-Mail Addresses is One thing, selling their passwords is another.
        I was trying to dereference Null Pointers before it was cool.

        evilfantasy

        • Malware Removal Specialist


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Sarah Palins Email... the "Hacker's" Interview
        « Reply #10 on: September 25, 2008, 12:06:30 PM »
        True, but what I'm not getting is there is no mention of the alternate email address that is required to retrieve account info.

        Just doesn't add up for me...

        drmsucks



          Specialist

          Re: Sarah Palins Email... the "Hacker's" Interview
          « Reply #11 on: September 25, 2008, 12:32:01 PM »
          By "alternate email address," do you mean an address to send the password to - after answering the recovery questions?
          If you don't have time to do it right
                          ...when will you have time to do it over?

          evilfantasy

          • Malware Removal Specialist


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Sarah Palins Email... the "Hacker's" Interview
          « Reply #12 on: September 25, 2008, 12:37:30 PM »
          Yep. You need one to finish the security questions when registering a new account.

          Siscorskiy



            Beginner
            Re: Sarah Palins Email... the "Hacker's" Interview
            « Reply #13 on: September 25, 2008, 05:20:01 PM »
            PWNED....
            I help you do more by doing less.

            kpac

            • Web moderator


            • Hacker

            • kpac®
            • Thanked: 184
              • Yes
              • Yes
              • Yes
            • Certifications: List
            • Computer: Specs
            • Experience: Expert
            • OS: Windows 7