Thousands of Hotmail/win live passwords leaked online

Soldato
OP
Joined
5 Jun 2005
Posts
20,772
Location
Southampton
I would do if I could actually get a gmail account now. Unfortunately it seems you're only allowed @googlemail.com now.

well there are plenty of ways around that my friend, after all you need to do is make google think your not in the UK, ;)

http://www.google.co.uk/#hl=en&sour...=&aq=2&oq=how+to+get+a+gm&fp=55b1114b05e94ce9

You can still use the "@gmail.com" extension with a "@googlemail.com" account I think :)

yeah you do, but when you mail people it comes from that and does not look as cool :)
 
Associate
Joined
22 Sep 2009
Posts
2,085
Location
Leicester
I'd be interested in that list also, because one of my e-mail accounts is on there... and Googling my e-mail addy is not helpful in the slightest :rolleyes:

I'll assume for now I'm safe, its likely phising (to be only 10,000 A-B) and I'd like to think I'm pretty sensible about strange e-mails.
 
Caporegime
Joined
30 Jun 2007
Posts
68,784
Location
Wales
I'd be interested in that list also, because one of my e-mail accounts is on there... and Googling my e-mail addy is not helpful in the slightest :rolleyes:

I'll assume for now I'm safe, its likely phising (to be only 10,000 A-B) and I'd like to think I'm pretty sensible about strange e-mails.

How do you know yours is on there?

Also lul phising fail.
 
Soldato
Joined
7 Apr 2004
Posts
4,212
how many digitis? I am just curious. Mine is usually 4 to 6 digits.

4 is too low tbh.

A lowercase 4 char password for example is 456976 combinations, easily brute forceable. You really need to be thinking >= 8 characters these days, good mix of lower/upper case and chuck in a few symbols too. The best thing to do is use keepass or something similar http://keepass.info/ Then just remember 1 master password, and have really strong unique 20 character passwords for each of your online accounts.

As said, this 'attack' is purely a result of people being silly or uneducated :rolleyes:
 
Soldato
Joined
7 Apr 2004
Posts
4,212
But can;t you only try 5 times every 15 minutes ?

So with that many combinations it would take months wouldn't it to brute force?

Yer fair point, it depends on the attack to be honest.

Say for example you somehow managed to break into a hotmail server and steal their hash of someones password, you could simply crack it offline pretty quickly. Going through the web front-end as you said would be infeasible though.
 
Back
Top Bottom