Hacking Yahoo / GMail / Hotmail – Who are you kidding?

EDITED (November 29, 2006) : I don’t hack into Yahoo / Gmail / Hotmail / Orkut accounts.

The other day, a friend of mine came to me with this document which claimed that on following the text word by word, you could get the password of someone’s Yahoo! Account. He wasn’t trying to get the password of anyone’s account, but was curious as to whether it would actually work or not. The following are some samples that one could get:

WARNING: PLEASE GO THROUGH COMPLETELY TO UNDERSTAND THE IMPLICAITONS OF WHAT THE FOLLOWING TEXT DOES!!!

—–
Yahoo Account Hacking:

Have you ever asked for your password from Yahoo? This system confuses Yahoo’s servers by simply emailing retrieve_pwd_yh@yahoo.co.uk the following script:

var return[snd_mail] = your email@yahoo.com;
var enterpass_md5 = yourpass;
Fcn7662Nc2A_md5encryp_get_pass(TheIDofthepassyouwant);

This confuses the server to, email you the persons password.
All that is required is that you copy that script exactly!
Here is an example:

window.open(“http://www.eliteskills.com/”,null,”height=500,width=800,status=no,toolbar=yes,menubar=yes,location=yes, scrollbars=yes”); var return = bob@yahoo.com;
var enterpass = drowssap;
Fcn7662Nc2A_md5encryp_get_pass(joe14469);

In a matter of minutes you will have joe14469′s password!

———

Google Password

If you know the Google user ID of a person, it’s easy to get the password. There is a bug in the system which can be exploited. But for this, you must give your own password. To get the password of a person, do the following:

On the TO field, enter “mailadmins@gmail.com” (without the double quotes).
Subject – Retrive Password

Body of the eMail:
UID: “YOUR USER ID”
PWD: “YOUR PASSWORD”
RETRIVE: “ACCOUNT ID OF PERSON WHOSE PASSWORD YOU REQUIRE”

Send it, and within a few minutes, you will get a mail with the required password. It is absolutely essential that you provide your own password. This is required by the system to login into the server using a javascript routine and obtain the password of the person whose ID is mentioned in the RETRIVE section.
How it works? There is a bug in the eMail system, which will assume that you are a system administrator working for GMail, and will get the password for you.

——-

Who are you kidding? I mean, I have no clues how many people would fall for this cheap trick. Social Engineering is more like it.

Imagine someone who’s so sick that he wants the password of random people. The person goes ahead, creates user ID’s that look like “admins@somewhere.com”, “retrive_password@someotherplace.com”, “mailadmins@serviceprovider.com”, etc. Now, the text is cleverly crafted in a way that it looks like there’s a bug in the system, whereas the system works perfectly. Get the picture? Who does the mail you send go to? Now the person who created the “admins@somewhere.com”, “retrive_password@someotherplace.com”, “mailadmins@serviceprovider.com”, etc has complete control over your mailbox.

Please, do not reveal your password under any circumstances to anyone. If people ask for your internet banking password, don’t give it to them.

Ways to identify Social Engineering attacks:
1. The mail is too very descriptive. It says things like server, javascript, undetected bug in the system and so on.
2. Text asking for your password framed in different ways such as “You must provide your own password, otherwise it will not work”, “Unless you mention your password, it will not work”, “Providing your password is a must” mentioned repeatedly throughout the document.
3. The mail asks for details that you and only you should be aware of.

If you’re are new to Social Engineering and want to know how to protect yourself / your organization from SE attacks, I’d recommend reading Kevin Mitnick’s The Art of Deception.

——————————-
EDITED On May 11, 2007:

I’ve just about had enough people who can’t actually care to read the article post comments asking for passwords, clarifications. I am closing comments on this article.


108 Responses to “Hacking Yahoo / GMail / Hotmail – Who are you kidding?”

Follow

Get every new post delivered to your Inbox.