Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

<< WAIT >>


aus+uk / uk.comp.homebuilt / Compromised Hotmail account and suspicious timing

SubjectAuthor
* Compromised Hotmail account and suspicious timingDavid
+* Re: Compromised Hotmail account and suspicious timingJeff Gaines
|`* Re: Compromised Hotmail account and suspicious timingAbandoned_Trolley
| `* Re: Compromised Hotmail account and suspicious timingDavid
|  `- Re: Compromised Hotmail account and suspicious timingDaniel James
`- Re: Compromised Hotmail account and suspicious timingDavid

1
Compromised Hotmail account and suspicious timing

<kmm0lgF96ohU1@mid.individual.net>

  copy mid

https://www.novabbs.com/aus+uk/article-flat.php?id=3865&group=uk.comp.homebuilt#3865

  copy link   Newsgroups: uk.comp.homebuilt
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: wib...@btinternet.com (David)
Newsgroups: uk.comp.homebuilt
Subject: Compromised Hotmail account and suspicious timing
Date: 16 Sep 2023 15:41:36 GMT
Lines: 34
Message-ID: <kmm0lgF96ohU1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net jZCnZjHqTc7nEzCxT9bNogeGYC96LoICiDoCODNokP1gp0MmCc
Cancel-Lock: sha1:nmn3Wa5BlZhbY4bIKB3R05J3+Bo= sha256:BpXmrLgWKu31MuHQtr9Ks/MQMeVm1QK6rFYBYWI7I8s=
User-Agent: Pan/0.140 (Chocolate Salty Balls; Unknown)
X-Antivirus: Avast (VPS 230916-4, 16/9/2023), Outbound message
X-Antivirus-Status: Clean
 by: David - Sat, 16 Sep 2023 15:41 UTC

We have just discovered that a friend's Hotmail account has been
compromised.

Not sure how because they are normally very cautious.

The interesting timing is because they have just bought a new laptop and I
helped with the configuration, and 2FA wasn't working because the account
had a (correct) phone number associated with it but this failed to ring
and supply the 2FA prompt.
[I suspect that M$ was assuming a mobile phone and tried to send a text to
a land line.].

Anyway we decided to change the 2FA setting to a Gmail account.
Because of the 2FA failure a wait of 30 days was put on any further
account activity.

Recently (about a week ago) another email was received saying the waiting
period was over.

Today phishing emails are going out from that account.

Correlation and causation, of course, but it does make me wonder.

Is this ringing bells with anyone?

Cheers

Dave R

--
AMD FX-6300 in GA-990X-Gaming SLI-CF running Windows 10 x64

Re: Compromised Hotmail account and suspicious timing

<xn0o6wu9f4b5sne008@news.individual.net>

  copy mid

https://www.novabbs.com/aus+uk/article-flat.php?id=3866&group=uk.comp.homebuilt#3866

  copy link   Newsgroups: uk.comp.homebuilt
Path: i2pn2.org!i2pn.org!usenet.goja.nl.eu.org!3.eu.feeder.erje.net!feeder.erje.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: jgnew...@outlook.com (Jeff Gaines)
Newsgroups: uk.comp.homebuilt
Subject: Re: Compromised Hotmail account and suspicious timing
Date: 16 Sep 2023 15:57:39 GMT
Lines: 10
Message-ID: <xn0o6wu9f4b5sne008@news.individual.net>
References: <kmm0lgF96ohU1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net Nd8cL9K9/XxtEnquIJcL9QMfQ37b9r8Lu8iWTu1kCC+lA0i6pS
Cancel-Lock: sha1:kqQXHOPZA+aZLG+UdSCdYmjdGIs= sha256:S1ozznMskV2jVhmBSJSjIDCOfbPnUa/1ojOFTZ9QVpY=
User-Agent: XanaNews/1.21-f3fb89f (x86; Portable ISpell)
X-Face: `{n`"d>nF^Uwzc:,L`j<I0Z`+o3aIFomb({]W!ey_aouI;EhEg9Q~,73RF,@{]-!$,A,z>,x
X-Ref: news.individual.net ~XNS:0000560A
 by: Jeff Gaines - Sat, 16 Sep 2023 15:57 UTC

On 16/09/2023 in message <kmm0lgF96ohU1@mid.individual.net> David wrote:

>[I suspect that M$ was assuming a mobile phone and tried to send a text to
>a land line.].

You have been able to text via a landline for 20 years now.

--
Jeff Gaines Dorset UK
The first five days after the weekend are the hardest.

Re: Compromised Hotmail account and suspicious timing

<ue4k76$3stmj$1@dont-email.me>

  copy mid

https://www.novabbs.com/aus+uk/article-flat.php?id=3867&group=uk.comp.homebuilt#3867

  copy link   Newsgroups: uk.comp.homebuilt
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: fre...@fred-smith.co.uk (Abandoned_Trolley)
Newsgroups: uk.comp.homebuilt
Subject: Re: Compromised Hotmail account and suspicious timing
Date: Sat, 16 Sep 2023 17:13:25 +0100
Organization: A noiseless patient Spider
Lines: 18
Message-ID: <ue4k76$3stmj$1@dont-email.me>
References: <kmm0lgF96ohU1@mid.individual.net>
<xn0o6wu9f4b5sne008@news.individual.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Sat, 16 Sep 2023 16:13:26 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="16baf435551b2a7927c6473edfac2264";
logging-data="4093651"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/9rlbq/hz9WBgQktaEJD+ANmhSA9ObP/1vPV1HHPdxMw=="
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.15.1
Cancel-Lock: sha1:m5ws02h3fFaIdT1tCrlpLpO5I1E=
In-Reply-To: <xn0o6wu9f4b5sne008@news.individual.net>
 by: Abandoned_Trolley - Sat, 16 Sep 2023 16:13 UTC

On 16/09/2023 16:57, Jeff Gaines wrote:
> On 16/09/2023 in message <kmm0lgF96ohU1@mid.individual.net> David wrote:
>
>> [I suspect that M$ was assuming a mobile phone and tried to send a
>> text to
>> a land line.].
>
> You have been able to text via a landline for 20 years now.
>

And the robot even leaves a message on your answering machine (for those
of you who can remember what that is)

--
random signature text inserted here

Re: Compromised Hotmail account and suspicious timing

<kmm8irF97g0U1@mid.individual.net>

  copy mid

https://www.novabbs.com/aus+uk/article-flat.php?id=3868&group=uk.comp.homebuilt#3868

  copy link   Newsgroups: uk.comp.homebuilt
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: wib...@btinternet.com (David)
Newsgroups: uk.comp.homebuilt
Subject: Re: Compromised Hotmail account and suspicious timing
Date: 16 Sep 2023 17:56:43 GMT
Lines: 23
Message-ID: <kmm8irF97g0U1@mid.individual.net>
References: <kmm0lgF96ohU1@mid.individual.net>
<xn0o6wu9f4b5sne008@news.individual.net> <ue4k76$3stmj$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net NxciTcSPH+eC9oqcAZTyBwDwb4LLVOhS1j7N+HelIKQ+1VZBmL
Cancel-Lock: sha1:Felbb+yheAQpayan//2xlkMfGfM= sha256:6y1uP2/I6MWimPvsFbfTdbIPgAfoaaop3fV1QIOAxNA=
User-Agent: Pan/0.140 (Chocolate Salty Balls; Unknown)
X-Antivirus: Avast (VPS 230916-4, 16/9/2023), Outbound message
X-Antivirus-Status: Clean
 by: David - Sat, 16 Sep 2023 17:56 UTC

On Sat, 16 Sep 2023 17:13:25 +0100, Abandoned_Trolley wrote:

> On 16/09/2023 16:57, Jeff Gaines wrote:
>> On 16/09/2023 in message <kmm0lgF96ohU1@mid.individual.net> David
>> wrote:
>>
>>> [I suspect that M$ was assuming a mobile phone and tried to send a
>>> text to a land line.].
>>
>> You have been able to text via a landline for 20 years now.
>>
>>
>
> And the robot even leaves a message on your answering machine (for those
> of you who can remember what that is)

I wonder why the phone didn't ring, then?
Even made a call to it to confirm that it was working.

--
AMD FX-6300 in GA-990X-Gaming SLI-CF running Windows 10 x64

Re: Compromised Hotmail account and suspicious timing

<ue5deo$1nag$1@dont-email.me>

  copy mid

https://www.novabbs.com/aus+uk/article-flat.php?id=3869&group=uk.comp.homebuilt#3869

  copy link   Newsgroups: uk.comp.homebuilt
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: dan...@me.invalid (Daniel James)
Newsgroups: uk.comp.homebuilt
Subject: Re: Compromised Hotmail account and suspicious timing
Date: Sun, 17 Sep 2023 00:24:26 +0100
Organization: Daniel James
Lines: 18
Message-ID: <ue5deo$1nag$1@dont-email.me>
References: <kmm0lgF96ohU1@mid.individual.net>
<xn0o6wu9f4b5sne008@news.individual.net> <ue4k76$3stmj$1@dont-email.me>
<kmm8irF97g0U1@mid.individual.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Sat, 16 Sep 2023 23:24:09 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="1175ed4cd574514280f9532c5d275c5e";
logging-data="56656"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+RR2VgikZh3pgBF/AQIg7P"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.15.1
Cancel-Lock: sha1:JvGcjfTHIi7IKYGxcckpXpqsBjw=
Content-Language: en-GB
In-Reply-To: <kmm8irF97g0U1@mid.individual.net>
 by: Daniel James - Sat, 16 Sep 2023 23:24 UTC

On 16/09/2023 18:56, David wrote:
> I wonder why the phone didn't ring, then?
> Even made a call to it to confirm that it was working.

IME it takes some time for BT's robots to read the text message and ring
through with the voice version; from minutes to days.

I used to have a landline phone that could handle SMS as SMS, but I
never set it up because BT wanted money for the privilege and I had a
perfectly good mobile for that sort of thing.

Last time I had to buy a new landline phone I ended up getting one that
doesn't handle SMS. Progress, I suppose ...

--
Cheers,
Daniel.

Re: Compromised Hotmail account and suspicious timing

<kmu8vlF97g0U2@mid.individual.net>

  copy mid

https://www.novabbs.com/aus+uk/article-flat.php?id=3886&group=uk.comp.homebuilt#3886

  copy link   Newsgroups: uk.comp.homebuilt
Path: i2pn2.org!i2pn.org!usenet.goja.nl.eu.org!3.eu.feeder.erje.net!feeder.erje.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: wib...@btinternet.com (David)
Newsgroups: uk.comp.homebuilt
Subject: Re: Compromised Hotmail account and suspicious timing
Date: 19 Sep 2023 18:52:37 GMT
Lines: 71
Message-ID: <kmu8vlF97g0U2@mid.individual.net>
References: <kmm0lgF96ohU1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net sfrogiy/O9GpZAQ3Qz8cFwazctlP5VV1FuuvSxKzdhF9yHj75d
Cancel-Lock: sha1:utSDE3ZFeKPSjNBOiW3HjB32SJI= sha256:3UGDfplT5gUJdevcJgTZ+Wd8aZBXOdmy/f/uuD2N+9w=
User-Agent: Pan/0.140 (Chocolate Salty Balls; Unknown)
X-Antivirus: Avast (VPS 230919-6, 19/9/2023), Outbound message
X-Antivirus-Status: Clean
 by: David - Tue, 19 Sep 2023 18:52 UTC

On Sat, 16 Sep 2023 15:41:36 +0000, David wrote:

> We have just discovered that a friend's Hotmail account has been
> compromised.
>
> Not sure how because they are normally very cautious.
>
> The interesting timing is because they have just bought a new laptop and
> I helped with the configuration, and 2FA wasn't working because the
> account had a (correct) phone number associated with it but this failed
> to ring and supply the 2FA prompt.
> [I suspect that M$ was assuming a mobile phone and tried to send a text
> to a land line.].
>
> Anyway we decided to change the 2FA setting to a Gmail account.
> Because of the 2FA failure a wait of 30 days was put on any further
> account activity.
>
> Recently (about a week ago) another email was received saying the
> waiting period was over.
>
> Today phishing emails are going out from that account.
>
> Correlation and causation, of course, but it does make me wonder.
>
> Is this ringing bells with anyone?

Update: I found a phishing email claiming to be from Microsoft dated the
day the compromise happened.
One of those "timing" this where an email from Microsoft was expected.
No admission from my friend, but circumstantial evidence looks pretty
solid.
Microsoft provide a security log for the account which showed a successful
log in from Nigeria at the expected date, then further successful log ins
from other devices around the world.

I reset the password using the newly activate 2FA with a Gmail address as
the second channel.

I then had a head scratcher because emails were going out but not being
received.
Being out of practice it took me a while and some Internet searching (Bing
not Google) to remind myself about redirects.
I looked at the configuration page for the Hotmail account using Outlook
web and there was no redirect showing.
However when I set up another redirect it all sprang back to life.
I cleared the redirect and all still seems to be working.

In this case, no real harm done as the subsequent phishing of the contacts
for Amazon gift vouchers for someone apparently in Canada were not
convincing.

Also fortunately my friend doesn't shop or bank on line.
Think Luddite.
So the email address could not be used to reset credentials on web sites
which could then be used to buy stuff.

All in all a salutary tale, and a reminder to be double wary if you are
expecting an email.

Cheers

Dave R

--
AMD FX-6300 in GA-990X-Gaming SLI-CF running Windows 10 x64

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor