PDA

View Full Version : Hacked email



Suppa Hobbit Mage
06-03-2011, 09:59 AM
So my email account from back when I worked at AOL was hacked about two weeks ago. I ran kapersky anti-virus I think it was and search and destroy, found nothing. Changed my password to letters, numbers and symbols (it was just a mix of upper/lower and numbers) and didn't think much of it.

Today at work I got email from my AOL account with a youtube vid link. I know there are ways to fake the from field, but not sure anymore how hard that is or not. Anyway, I changed the PW again, checked sent mail but there was nothing (whereas before there was a shitton of spam emails sent from the account).

Anyway, anyone have any ideas? I only use the webclient, and then probably only once every two weeks. Before I was hacked, I'd get the emails on my blackberry, but I since removed the app. I access AOL via IE from work and from home. It's frustrating as shit because I've never been hacked before in my life, ever. I always use complex PWs, and honestly don't download things except addons for WoW (not even porn!).

Curious if anyone has any recommendations.

Inspire
06-03-2011, 10:01 AM
Maybe Rogane had better luck with AOL instead of GMAIL.

http://forum.gsplayers.com/showthread.php?t=62814

NocturnalRob
06-03-2011, 10:03 AM
I did it.

Keller
06-03-2011, 10:04 AM
AOL, Chip?

Keller
06-03-2011, 10:04 AM
S(not even porn!).

Much simpler to stream it, anyways.

Drew
06-03-2011, 10:09 AM
You're changing your PW via a webpage? Use firefox with noscript running. Unless the program is actually on your computer that should kill any sort of script based attack. Avast is a good free anti-virus to download and run.

Dyslexia
06-03-2011, 10:16 AM
try malwarebytes too, couldnt hurt

Cephalopod
06-03-2011, 10:20 AM
Before trying to change the password from your computer (so it doesn't just get logged again):

rkill (http://www.bleepingcomputer.com/download/anti-virus/rkill)

SUPERAntiSpyware (http://www.superantispyware.com/)

Malwarebytes (http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button)

In that order. (I used to just suggest Malwarebytes, but I've found SUPERAntiSpyware -- despite the stupid name -- to be amazingly good at catching stuff that normally slips through.)

Then do what Drew suggested.

You could also change the AOL password by using the mobile browser on your Blackberry, just until you get your computer cleaned up.

Kyra231
06-03-2011, 10:35 AM
Before trying to change the password from your computer (so it doesn't just get logged again):

rkill (http://www.bleepingcomputer.com/download/anti-virus/rkill)

SUPERAntiSpyware (http://www.superantispyware.com/)

Malwarebytes (http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button)

In that order. (I used to just suggest Malwarebytes, but I've found SUPERAntiSpyware -- despite the stupid name -- to be amazingly good at catching stuff that normally slips through.)

Then do what Drew suggested.

You could also change the AOL password by using the mobile browser on your Blackberry, just until you get your computer cleaned up.

I second changing the pw from a different pc. Also try opening a program that requires your pw & fill the fields with gibberish. Leave it open then run your malware/spyware/etc programs. Some keyloggers will lie dormant & undetected until you have a program open that calls for your pw.

Suppa Hobbit Mage
06-03-2011, 10:39 AM
Before trying to change the password from your computer (so it doesn't just get logged again):

rkill (http://www.bleepingcomputer.com/download/anti-virus/rkill)

SUPERAntiSpyware (http://www.superantispyware.com/)

Malwarebytes (http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button)

In that order. (I used to just suggest Malwarebytes, but I've found SUPERAntiSpyware -- despite the stupid name -- to be amazingly good at catching stuff that normally slips through.)

Then do what Drew suggested.

You could also change the AOL password by using the mobile browser on your Blackberry, just until you get your computer cleaned up.

See, my thoughts (and thus the reason I removed the app from my Blackberry) were that my BB got hacked or something. All my work on it is encrypted and PW protected on top of that, but the AOL is not. I dunno, the most frustrating part is I can't think of doing anything that could have caused it at all. I hadn't downloaded anything recently, except on my BB.

Archigeek
06-03-2011, 11:26 AM
I don't have any advice to offer, but you aren't the only one to have had an AOL account hacked recently. I got spam from Ardwen's AOL email recently, and he ran a full slate of anti-malware/spam/virus software and found nothing as well. One thing he did mention, was that all of the email addy's that were sent spam were very old email addy's. Also, like you, all of the "sent emails" were in the sent email folder. It sounds like you guys might have been hit by the same thing.

g++
06-03-2011, 11:31 AM
Yahoo/Aol accounts get hacked constantly. It has nothing to do with your personal computer set up the accounts and the servers their on are vulnerable.

Ardwen
06-03-2011, 11:31 AM
Yep. pretty much the same thing. still havent found a thing with now 8 different spyware/virus programs, via friefox download.chrome download or ie download.

Mailed a bunch of crap addresses out to maybe 10 percent of my old contacts and nothing since.

Cephalopod
06-03-2011, 11:45 AM
My gmail account was hacked recently. I happened to be online doing other emails when it spammed a ton of people, and I saw a warning in gmail saying a foreign IP address was accessing my account.

To be fair, my password on that gmail account was very weak, so I just assume it was brute-force or farmed from some random site where I used that email address and the same weak password.

An example would be if you used a Gawker-related site -- their password database was compromised a few months ago, and it's the kind of place where people will register with an email address and the same password as they use for their email address.

The lesson: don't use weak passwords on sensitive accounts, and don't use the same password for anything you register for unless it's something you don't care about getting hacked. (i.e. my PC account has a weak password. My bank account does not.)

Suppa Hobbit Mage
06-03-2011, 11:47 AM
Yeah, mine sent emails out to pretty much everyone that I worked with when I worked there, most of which are dead accounts now. I might just cancel the address, but it's hard to let go of one you've had for 16 years :/

Ardwen
06-03-2011, 11:48 AM
Yep same address since 96 obviously for me

phantasm
06-03-2011, 05:25 PM
Was your blackberry using public/open/shared wifi. its pretty damned easy to sniff and steal session cookies for multitudes of websites these days. Make sure 100% of your wifi traffic is going through HTTPS or some other encrypted tunnel.

Check out Firesheep the firefox addon for stealing session cookies.

phantasm
06-03-2011, 05:28 PM
Oh and Facesniff the android app for hijacking facebook sessions on the go.

Deadelf
06-03-2011, 05:45 PM
Yeah this is why every couple years I just say screw it and get rid of my email and get a new one. Just saves spam and other shit like this. :(

Ardwen
06-03-2011, 06:40 PM
I always thought that was cause you were wanted for some anti-government activities in the 60s

Archigeek
06-03-2011, 06:52 PM
What if it's a clever one-shot and then self-delete worm? The only way to find it would be to go back to a reboot point? And then of course you'd potentially be reinfecting yourself.

g++
06-03-2011, 07:07 PM
It was likely a brute force login attack or a server exploit. I literally get this "My yahoo account was hacked" thing like twice a week from my users. There arent enough human beings in the world to be launching this many worms and packet sniffers. Ive never heard of anyone having a credit card used or billing statement or whatever its like 99.9999999999% spammers hacking servers and bombing login screens to get into accounts to send viagra spam.

The odds james bond is sitting outside your window with a packet sniffer to find out what your uncle forwarded you in 97 are low.

TheEschaton
06-03-2011, 07:27 PM
Did you get pictures of your weiner sent out, SHM?

4a6c1
06-03-2011, 07:40 PM
HACKERS ARE ALL MANHATING LESBIANS ARGHHH

iJin
06-03-2011, 07:45 PM
What in the fucking fuck are you even still doing with a AOL email.

Gelston
06-03-2011, 08:10 PM
It attachs to AIM.

Warriorbird
06-03-2011, 08:12 PM
HACKERS ARE ALL MANHATING LESBIANS ARGHHH

What I'm getting from this is Rojo, while dressed as Lizbeth Salander, hacked SHM's Blackberry.

4a6c1
06-03-2011, 08:16 PM
WARRIORBIRD IS A MANHATING LESBIAN TOO

Warriorbird
06-03-2011, 08:17 PM
WARRIORBIRD IS A MANHATING LESBIAN TOO

Shit. Busted. And I'd still feel weird about that Japanese "chick."

4a6c1
06-03-2011, 08:18 PM
Femboner.

diethx
06-03-2011, 08:20 PM
What in the fucking fuck are you even still doing with a AOL email.

Some of us were born before 2000 and are too lazy to change emails on everything. DON'T HATE.

iJin
06-03-2011, 08:46 PM
I was born before 2000. NO EXCUSE.

Back
06-03-2011, 09:29 PM
Yeah, mine sent emails out to pretty much everyone that I worked with when I worked there, most of which are dead accounts now. I might just cancel the address, but it's hard to let go of one you've had for 16 years :/

I let go of mine in 2005. I understand the nostalgia. It was my first email address. Tell you what though. Canceling it was a pain in the ass. Whoever they have in the call centers at AOL are tenacious sobs. It was like pulling nails to close that account.

Gelston
06-03-2011, 10:24 PM
AOL is free if you aren't using them for dial up, why did you bother calling?

Delias
06-04-2011, 12:41 AM
I was born before 2000. NO EXCUSE.

Barely.

iJin
06-04-2011, 02:40 AM
Barely.

While you have been existing entirely too long.

Deadelf
06-04-2011, 03:20 AM
I always thought that was cause you were wanted for some anti-government activities in the 60s

I don't know what you are talking about and those missions didn't take place over the iron curtain no matter what anyone claims. :>

Deadelf
06-04-2011, 03:27 AM
I let go of mine in 2005. I understand the nostalgia. It was my first email address. Tell you what though. Canceling it was a pain in the ass. Whoever they have in the call centers at AOL are tenacious sobs. It was like pulling nails to close that account.


No shit. I gave mine up around 10 years ago give or take a year. They kept offering me shit and trying to talk me out of it. I kept telling them that I didn't use them, GEnie, Compuserve, Prodigy etc anymore and no matter how bad Steve Case wanted to continue to send me email I wasn't gonna keep the damn thing.

Speaking of anyone recall when the AOL software was a "quasi" windows looking DOS based program. It looked so slick in comparison to my GEnie software for logging into GEnie and checking bbs, email etc. How things have changed.

diethx
06-04-2011, 11:53 AM
While you have been existing entirely too long.

OHHHH SNAP

Truthfully I dunno what the big deal is. It's been free on the web for ages unless you actually use the AOL software, and I'd be really surprised if there was still anyone using that except in maybe eastern Europe or something where everything is 20 years behind us. I have several emails, and one of them is my old AOL mail which I will probably have and use until AOL shuts down for good.

Suppa Hobbit Mage
06-06-2011, 10:39 AM
I have mine because it was used for work while I worked there, and it's free, and I actually like it. It's not like I had a reason to drop it, until now. I went in over the weekend on a reimaged laptop I have and changed all the PWs again, and blocked all email except from my family. Gonna leave that in place for 6 months or so.

I'm buying a new desktop in the near future since mine crapped out over the weekend anyway (the vid card did anyway), so I'm not too worried about it.

diethx
06-06-2011, 12:26 PM
You're buying a new computer because your video card crapped out? Do you need a new computer for gaming or something anyway? Or are you just about to waste a bunch of money?

Parkbandit
06-06-2011, 12:31 PM
Unless the computer is less than 18 months old.. it's probably better to just buy a new computer.

Keller
06-06-2011, 12:47 PM
Unless the computer is less than 18 months old.. it's probably better to just buy a new computer.

Unless you've got a VAULT OF GOLD COINS, and then you can lower that to 18 days old.

Suppa Hobbit Mage
06-06-2011, 03:11 PM
You're buying a new computer because your video card crapped out? Do you need a new computer for gaming or something anyway? Or are you just about to waste a bunch of money?

I've upgraded the card twice now, it's 5 years old is all. Time for a new one.

diethx
06-06-2011, 03:21 PM
Oh, okay.

Ardwen
06-10-2011, 02:39 PM
looks like another GSer has the hacked email heh, Cr8dlme Thats the original Kimsem I think isnt it?

diethx
06-10-2011, 05:11 PM
Yes it is.

Warriorbird
06-10-2011, 05:18 PM
looks like another GSer has the hacked email heh, Cr8dlme Thats the original Kimsem I think isnt it?

Jinsem.

Ardwen
06-11-2011, 12:50 AM
yeah whatever his mail is doing what mine did the bastard