Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

'Password Recovery' Services May Be Hackers for Hire

Services that promise to help you find your lost passwords may make their living by cracking the passwords of others, IBM researcher says

You've seen the ads on the Web: A service provider promises to "recover" lost passwords from your Webmail services, even if you've forgotten the log-on information or use multiple services. But if you look closer, you may notice something else: Those same services can also help you crack others' Webmail accounts.

Gunter Ollmann, chief security strategist at IBM's Internet Security Systems unit, published a blog about the password cracking services on Monday, after doing some research on these legitimate-looking services. What he found might make you think twice about using Webmail services -- or at least think more carefully about what data you put into your Webmail messages.

Webmail services such as Gmail and Hotmail are widely used as a quick, low-cost alternative to more sophisticated email services offered by ISPs or corporations, Ollmann observes. Many users have at least one Webmail account -- and sometimes more -- that they use for personal messages when they are on the Web and can't get easy access to their full-function email accounts.

But Webmail accounts are not particularly secure, Ollmann warns. For between $300 to $600, a hacker can find a full suite of Webmail cracking tools on the 'Net, complete with the ability to do brute-force "guessing" of simple passwords and enhanced tools for penetrating the CAPTCHA authentication methods used on Webmail services, he notes.

And now those capabilities are being turned into hack-for-hire services, Ollmann says. Such services have been around for about two years, he notes, but today's CAPTCHA-breaking methods have become so effective that for about $100, the service provider can not only promise to give you the password to a specific Webmail account, but it can also promise to give you subsequent passwords if the legitimate owner should change passwords.

"These services can essentially give you a 'lifetime service contract' that you will always know the password to that account," Ollmann said.

As storage becomes less expensive, many Webmail services are offering larger and larger mailbox archives, allowing users to store messages for years at a time, Ollmann notes. And because they focus on simplicity and low cost, these services generally don't offer an encryption option, so anyone with the right password can read all the messages in the archives.

Some password recovery services come right out and offer a variety of applications for their services, such as the ability to investigate the activities of a spouse who's suspected of cheating. When managers leave a company, they often leave Webmail as a forwarding address, which may open them up to scrutiny by those who would like to know who they're taking with them, Ollmann observes.

Because of the relative simplicity of Webmail services, there isn't much that users can do to protect themselves from these hack-for-hire services, Ollmann says. "The best thing you can do is to use strong passwords, which makes them more difficult to crack," he says. Most law enforcement agencies aren't investigating the hack-for-hire services because they tend to target only individual users for a few hundred dollars, "which is barely a blip on the screen for law enforcement," Ollmann observes.

When Webmail services first came on the scene, some enterprises experimented with blocking or filtering them, Ollmann stated. Today, however, it would be difficult for any company to set a policy against using Webmail services, because such services are so broadly used and because there is no easy way to enforce the policy, he says.

"Your best bet is to educate your users about the vulnerabilities of these services, and discourage them from using their Webmail accounts for transmitting company information or other sensitive data," Ollmann says. Users also should stay away from the services themselves, many of which are based in Russia or southeast Asia and can be recognized by the stilted English grammar in their service descriptions, he notes.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • IOActive
  • MessageLabs Ltd.
  • StillSecure

    Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Oldest First  |  Newest First  |  Threaded View
    Stop Defending Everything
    Kevin Kurzawa, Senior Information Security Auditor,  2/12/2020
    Small Business Security: 5 Tips on How and Where to Start
    Mike Puglia, Chief Strategy Officer at Kaseya,  2/13/2020
    5 Common Errors That Allow Attackers to Go Undetected
    Matt Middleton-Leal, General Manager and Chief Security Strategist, Netwrix,  2/12/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon
    Current Issue
    6 Emerging Cyber Threats That Enterprises Face in 2020
    This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
    Flash Poll
    How Enterprises Are Developing and Maintaining Secure Applications
    How Enterprises Are Developing and Maintaining Secure Applications
    The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2019-20477
    PUBLISHED: 2020-02-19
    PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.
    CVE-2019-20478
    PUBLISHED: 2020-02-19
    In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this issue affects developers who are unaware of the need to use methods such as safe_load in these use cases.
    CVE-2011-2054
    PUBLISHED: 2020-02-19
    A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper in...
    CVE-2015-0749
    PUBLISHED: 2020-02-19
    A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker ...
    CVE-2015-9543
    PUBLISHED: 2020-02-19
    An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is rel...