Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

'Password Recovery' Services May Be Hackers for Hire

Services that promise to help you find your lost passwords may make their living by cracking the passwords of others, IBM researcher says

You've seen the ads on the Web: A service provider promises to "recover" lost passwords from your Webmail services, even if you've forgotten the log-on information or use multiple services. But if you look closer, you may notice something else: Those same services can also help you crack others' Webmail accounts.

Gunter Ollmann, chief security strategist at IBM's Internet Security Systems unit, published a blog about the password cracking services on Monday, after doing some research on these legitimate-looking services. What he found might make you think twice about using Webmail services -- or at least think more carefully about what data you put into your Webmail messages.

Webmail services such as Gmail and Hotmail are widely used as a quick, low-cost alternative to more sophisticated email services offered by ISPs or corporations, Ollmann observes. Many users have at least one Webmail account -- and sometimes more -- that they use for personal messages when they are on the Web and can't get easy access to their full-function email accounts.

But Webmail accounts are not particularly secure, Ollmann warns. For between $300 to $600, a hacker can find a full suite of Webmail cracking tools on the 'Net, complete with the ability to do brute-force "guessing" of simple passwords and enhanced tools for penetrating the CAPTCHA authentication methods used on Webmail services, he notes.

And now those capabilities are being turned into hack-for-hire services, Ollmann says. Such services have been around for about two years, he notes, but today's CAPTCHA-breaking methods have become so effective that for about $100, the service provider can not only promise to give you the password to a specific Webmail account, but it can also promise to give you subsequent passwords if the legitimate owner should change passwords.

"These services can essentially give you a 'lifetime service contract' that you will always know the password to that account," Ollmann said.

As storage becomes less expensive, many Webmail services are offering larger and larger mailbox archives, allowing users to store messages for years at a time, Ollmann notes. And because they focus on simplicity and low cost, these services generally don't offer an encryption option, so anyone with the right password can read all the messages in the archives.

Some password recovery services come right out and offer a variety of applications for their services, such as the ability to investigate the activities of a spouse who's suspected of cheating. When managers leave a company, they often leave Webmail as a forwarding address, which may open them up to scrutiny by those who would like to know who they're taking with them, Ollmann observes.

Because of the relative simplicity of Webmail services, there isn't much that users can do to protect themselves from these hack-for-hire services, Ollmann says. "The best thing you can do is to use strong passwords, which makes them more difficult to crack," he says. Most law enforcement agencies aren't investigating the hack-for-hire services because they tend to target only individual users for a few hundred dollars, "which is barely a blip on the screen for law enforcement," Ollmann observes.

When Webmail services first came on the scene, some enterprises experimented with blocking or filtering them, Ollmann stated. Today, however, it would be difficult for any company to set a policy against using Webmail services, because such services are so broadly used and because there is no easy way to enforce the policy, he says.

"Your best bet is to educate your users about the vulnerabilities of these services, and discourage them from using their Webmail accounts for transmitting company information or other sensitive data," Ollmann says. Users also should stay away from the services themselves, many of which are based in Russia or southeast Asia and can be recognized by the stilted English grammar in their service descriptions, he notes.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • IOActive
  • MessageLabs Ltd.
  • StillSecure

    Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    DevSecOps: The Answer to the Cloud Security Skills Gap
    Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
    Attackers' Costs Increasing as Businesses Focus on Security
    Robert Lemos, Contributing Writer,  11/15/2019
    Human Nature vs. AI: A False Dichotomy?
    John McClurg, Sr. VP & CISO, BlackBerry,  11/18/2019
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Write a Caption, Win a Starbucks Card! Click Here
    Latest Comment: -when I told you that our cyber-defense was from another age
    Current Issue
    Navigating the Deluge of Security Data
    In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
    Flash Poll
    Rethinking Enterprise Data Defense
    Rethinking Enterprise Data Defense
    Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2019-15073
    PUBLISHED: 2019-11-20
    An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies and universities.
    CVE-2019-15072
    PUBLISHED: 2019-11-20
    The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities.
    CVE-2019-15071
    PUBLISHED: 2019-11-20
    The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail syste...
    CVE-2019-6176
    PUBLISHED: 2019-11-20
    A potential vulnerability reported in ThinkPad USB-C Dock Firmware version 3.7.2 may allow a denial of service.
    CVE-2019-6184
    PUBLISHED: 2019-11-20
    A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalation.