Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

'Password Recovery' Services May Be Hackers for Hire

Services that promise to help you find your lost passwords may make their living by cracking the passwords of others, IBM researcher says

You've seen the ads on the Web: A service provider promises to "recover" lost passwords from your Webmail services, even if you've forgotten the log-on information or use multiple services. But if you look closer, you may notice something else: Those same services can also help you crack others' Webmail accounts.

Gunter Ollmann, chief security strategist at IBM's Internet Security Systems unit, published a blog about the password cracking services on Monday, after doing some research on these legitimate-looking services. What he found might make you think twice about using Webmail services -- or at least think more carefully about what data you put into your Webmail messages.

Webmail services such as Gmail and Hotmail are widely used as a quick, low-cost alternative to more sophisticated email services offered by ISPs or corporations, Ollmann observes. Many users have at least one Webmail account -- and sometimes more -- that they use for personal messages when they are on the Web and can't get easy access to their full-function email accounts.

But Webmail accounts are not particularly secure, Ollmann warns. For between $300 to $600, a hacker can find a full suite of Webmail cracking tools on the 'Net, complete with the ability to do brute-force "guessing" of simple passwords and enhanced tools for penetrating the CAPTCHA authentication methods used on Webmail services, he notes.

And now those capabilities are being turned into hack-for-hire services, Ollmann says. Such services have been around for about two years, he notes, but today's CAPTCHA-breaking methods have become so effective that for about $100, the service provider can not only promise to give you the password to a specific Webmail account, but it can also promise to give you subsequent passwords if the legitimate owner should change passwords.

"These services can essentially give you a 'lifetime service contract' that you will always know the password to that account," Ollmann said.

As storage becomes less expensive, many Webmail services are offering larger and larger mailbox archives, allowing users to store messages for years at a time, Ollmann notes. And because they focus on simplicity and low cost, these services generally don't offer an encryption option, so anyone with the right password can read all the messages in the archives.

Some password recovery services come right out and offer a variety of applications for their services, such as the ability to investigate the activities of a spouse who's suspected of cheating. When managers leave a company, they often leave Webmail as a forwarding address, which may open them up to scrutiny by those who would like to know who they're taking with them, Ollmann observes.

Because of the relative simplicity of Webmail services, there isn't much that users can do to protect themselves from these hack-for-hire services, Ollmann says. "The best thing you can do is to use strong passwords, which makes them more difficult to crack," he says. Most law enforcement agencies aren't investigating the hack-for-hire services because they tend to target only individual users for a few hundred dollars, "which is barely a blip on the screen for law enforcement," Ollmann observes.

When Webmail services first came on the scene, some enterprises experimented with blocking or filtering them, Ollmann stated. Today, however, it would be difficult for any company to set a policy against using Webmail services, because such services are so broadly used and because there is no easy way to enforce the policy, he says.

"Your best bet is to educate your users about the vulnerabilities of these services, and discourage them from using their Webmail accounts for transmitting company information or other sensitive data," Ollmann says. Users also should stay away from the services themselves, many of which are based in Russia or southeast Asia and can be recognized by the stilted English grammar in their service descriptions, he notes.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • IOActive
  • MessageLabs Ltd.
  • StillSecure

    Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 4/7/2020
    The Coronavirus & Cybersecurity: 3 Areas of Exploitation
    Robert R. Ackerman Jr., Founder & Managing Director, Allegis Capital,  4/7/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Write a Caption, Win a Starbucks Card! Click Here
    Latest Comment: This comment is waiting for review by our moderators.
    Current Issue
    6 Emerging Cyber Threats That Enterprises Face in 2020
    This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
    Flash Poll
    State of Cybersecurity Incident Response
    State of Cybersecurity Incident Response
    Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2019-20637
    PUBLISHED: 2020-04-08
    An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connecti...
    CVE-2020-11650
    PUBLISHED: 2020-04-08
    An issue was discovered in iXsystems FreeNAS 11.2 and 11.3 before 11.3-U1. It allows a denial of service.
    CVE-2020-11653
    PUBLISHED: 2020-04-08
    An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
    CVE-2020-2732
    PUBLISHED: 2020-04-08
    A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.
    CVE-2020-1627
    PUBLISHED: 2020-04-08
    A vulnerability in Juniper Networks Junos OS on vMX and MX150 devices may allow an attacker to cause a Denial of Service (DoS) by sending specific packets requiring special processing in microcode that the flow cache can't handle, causing the riot forwarding daemon to crash. By continuously sending ...