On BNET: Why should anyone hire you?
BNET Business Network:
BNET
TechRepublic
ZDNet

September 18th, 2008

Attacker: Hacking Sarah Palin's email was easy

Posted by Dancho Danchev @ 5:11 pm

Categories: Browsers, Governments, Hackers, Passwords, Privacy, United States of America, Yahoo!

Tags: Sarah Palin, Email Security Question, Yahoo! Inc., Dancho Danchev

Yahoo Security QuestionsA college student identified as Rubico has claimed responsibility for hacking into Sarah Palin’s personal email, and provided a detailed 1st person account of how he hacked into the email account using the password “popcorn” which he managed to reset by successfully answering her security question “Where did you meet your spouse?” by Googling for the answer :

“Hello, /b/ as many of you might already know, last night sarah palin’s yahoo was “hacked” and caps were posted on /b/, i am the lurker who did it, and i would like to tell the story. In the past couple days news had come to light about palin using a yahoo mail account, it was in news stories and such, a thread was started full of newfags trying to do something that would not get this off the ground, for the next 2 hours the acct was locked from password recovery presumably from all this bullshit spamming.

after the password recovery was reenabled, it took seriously 45 mins on wikipedia and google to find the info, Birthday? 15 seconds on wikipedia, zip code? well she had always been from wasilla, and it only has 2 zip codes (thanks online postal service!) the second was somewhat harder, the question was “where did you meet your spouse?” did some research, and apparently she had eloped with mister palin after college, if youll look on some of the screenshits that I took and other fellow anon have so graciously put on photobucket you will see the google search for “palin eloped” or some such in one of the tabs. I found out later though more research that they met at high school, so I did variations of that, high, high school, eventually hit on “Wasilla high” I promptly changed the password to popcorn and took a cold shower.”

Originally blamed for the email hijacking, the Anonymous movement against the Church of Scientology has distanced from the hack :

“One of the main tenets of the anonymous movement against the Church of Scientology is to stay legal. Anonymous is no fixed group, just a term for anyone who acts without giving their name. We don’t know who is responsible for the hack on Sarah Palin’s mail account or what their attitudes to Scientology or anything else are. For us, they are anonymous, because we don’t know who they are and they are not us.”

Meanwhile, the owner of the Ctunnel.com service recently commented that if the attacker’s screenshot didn’t include theWikileaks Palin Defaced complete URl using Ctunnel.com it would have been hard to track him down through his service since a lot of people login to their Yahoo mailboxes while using it. And since the attacker did include the complete URL, and according to him did a mistake by using a single proxy service next to taking advantage of “proxy chaining” by using multiple different proxy servers/services across the globe, the FBI has already approached the owner of Ctunnel.com.

It’s also worth pointing out that in the time of posting this, Wikileaks.org’s article on “Sarah Palin Yahoo account 2008” has been defaced with the following message, reminding us that Wikileaks has a “fan club” too :

“I NOW HACK THIS WEBSITE! AREN’T YOUR PROUD OF ME, WIKILEAKS. I CAN PLAY YOUR GAME TOO!!!”

Gmail Security QuestionsThe massive media coverage is covering nothing else but an old school password reset tactic made possible due to the oversupply of personal information regarding the victim. Moreover, this incident once again puts the “security question vulnerability” in the spotlight. Last month, a posting at SecuriTeam’s blogs reasonably pointed out how personalizing the security question to something a little less obvious, is a feature currently offered only by Gmail, which shouldn’t be the case despite the fact that anyone can give an entirely different answer to each of the common “security” questions asked :

“Anyone that knows my address can easily figure out the name of my first school or my high school mascot. All of my neighbors, family and friends know both my dog’s name and my dad’s middle name, and everybody in the world knows I just LOVE the Lakers. As for my wife and me, the people who attended our wedding had the chance to hear about it in the ceremony - in case you couldn’t make it, we met on a roof of a bus, in Ladakh, India in 1994…

The fact that the answer to each of the security questions above is relatively easy to find out, makes them a security vulnerability in my Yahoo! account. By letting me make a security key based on the name of my first school, Yahoo! actually puts me at risk, allowing anyone that knows where I live to hijack my account. It’s like saying “We have the greatest lock to protect your house. Now, why don’t we hide the key under the mat”.”

Hacking is supposed to be about intellectual exploration, so resetting the password of someone’s Yahoo mailbox no matter if it’s the Pope, requires no more than two brain cells put into action. However, the political consequences and the long-term impact of this hack are an entirely different topic yet to be discussed based on the interpretation of the data found within.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 95 Talkback(s)
LOL!
This is an old story, but I gotta say I'm enjoying reading reader's responses more than any other story! Thanks, Fred.... (Read the rest)
Posted by: LiLac22281 Posted on: 05/21/09 You are currently: a Guest | | Terms of Use
The hacker could use a life  LBiege | 09/18/08
My guess is the prison system  John Zern | 09/18/08
Prison  samp1024 | 09/18/08
For her, May be  nucrash | 09/19/08
If he gets life, Palin should be fined.  nucrash | 09/19/08
huh?  cuba_pete@... | 09/19/08
So you're saying  thomasmarshall3@... | 09/19/08
I don't know  Jxn | 09/20/08
We are not as smart as you  aldotcom | 09/21/08
computer crimes are way overpunished  pcguy777 | 09/22/08
and every night  decan9@... | 09/19/08
I applaud the Hacker  nucrash | 09/19/08
Lets Just Think This Through,  epaph | 09/19/08
Did any of the posters read what this guy  walterclark@... | 09/19/08
Yep!  swampcat@... | 09/19/08
I have a question  Andrae420 | 10/10/08
premature  LiLac22281 | 05/21/09
Just think it through  garyrice@... | 09/19/08
yes prosecute him  epaph | 09/22/08
OK  frabjous | 09/19/08
thanks for the tip  epaph | 09/22/08
i think they want it, to be easy to hack  pcguy777 | 09/22/08
RE:  alincicome@... | 09/18/08
RE:  CharlesRKiss | 09/18/08
Security  CharlesRKiss | 09/18/08
Red Herring  JeffSmado | 09/18/08
RE:  Telix | 09/18/08
No, she is going to use a different question  nucrash | 09/19/08
RE: big egos  Anonybus | 09/19/08
RE: Security happy  sys_engineer | 09/19/08
Security  lwhite@... | 09/19/08
Text messages are dope!  zmud | 09/19/08
Obama Army of Creeps  Obama Army of Creeps | 09/19/08
WTF does Obama or McCain have to do with this?  ColdFusion_z | 09/19/08
Post the Info or Shut Up!  CheezHead59 | 09/22/08
somthing to think about  epaph | 09/23/08
What about the current administration  polar_bare | 09/19/08
Yep...and nothing to do with this  ColdFusion_z | 09/19/08
Come on  bnjamin_breeg@... | 09/22/08
Obama Army of Creeps  Daiv_Skinner | 09/19/08
Message has been deleted.  swampcat@... | 09/19/08
Your opinion?  CheezHead59 | 09/22/08
Another slobbering republican  michael.patrick@... | 09/19/08
A good excuse to delete her accounts  MarkoP | 09/19/08
Wow... conspiracy theory much?  James T. Kirk | 09/19/08
Start reading the newspapers buddy  MarkoP | 09/19/08
Your proof is you read it ....  ShadeTree | 09/19/08
Go easy on him....  James T. Kirk | 09/19/08
Not the Times  nfhiggs@... | 09/19/08
LOL (nt)  James T. Kirk | 09/19/08
good excuse  Paulc0222 | 09/19/08
My Dad used to feel the same way about Donny and Marie  M.W.H. | 09/19/08
Amazing contrast  frabjous | 09/19/08
The VP  aldotcom | 09/21/08
LOL!  LiLac22281 | 05/21/09
Back on your meds please.  CheezHead59 | 09/22/08
A good excuse to delete her accounts before investigators see them  MarkoP | 09/19/08
I'm sure Yahoo has backups. NT  ThereThere | 09/19/08
good lord!  nfhiggs@... | 09/19/08
TazerGATE, you hole.  aldotcom | 09/21/08
Coiincidence Theorists Deny Possibilty that Politicians are Corrupt  MarkoP | 09/19/08
are we missing something?  fred.montney@... | 09/19/08
What a Joke  marketmaven | 09/19/08
RE: Why all the chatter about the hack?  lostark98 | 09/19/08
You don't have a yahoo acct?  decan9@... | 09/19/08
Scary!  cachemein | 09/19/08
Worse than scary!  lostark98 | 09/19/08
Security blankets  w_c_mead | 09/19/08
I'm sure the hack WAS easy--  nancyjones36507@... | 09/19/08
I have seen the samples posted...  Wolfie2K3 | 09/20/08
RE: Sec?flaws  arianesysinc@... | 09/19/08
A rare flash  cachemein | 09/19/08
Absolutely agree, now what's that imply about Palin?  llamasaki | 09/19/08
LOL!  LiLac22281 | 05/21/09
RE:security  lwhite@... | 09/19/08
RE: gov.palin@yahoo.com  nellwal@... | 09/19/08
Fixed Pasword Reset Questions are a Problem  mesocyclone | 09/19/08
Simple Really  ManoaHI | 09/19/08
RE: Freudean slip  favorsham | 09/19/08
lol  LiLac22281 | 05/21/09
RE: Hacker?  xgi | 09/19/08
RE:  JGSantel | 09/19/08
Prison sounds appropos  thomasmarshall3@... | 09/19/08
Wikis get vandalized, not defaced  ghost_in_shell | 09/19/08
RE:  drjohnk | 09/20/08
RE: Rush accuses "Obama thugs"  lobs@... | 09/20/08
RE:  Fred Nurks | 09/21/08
LOL!  LiLac22281 | 05/21/09
RE: Passwords  dmhunter@... | 09/21/08
Many an email provider  Arun (sreearun) | 09/21/08
RE: the Passwords  obietemp | 09/22/08
YES BUT, the RESET ONLY GOES TO THE ...  pcguy777 | 09/22/08
HOW to EASILY DEFEAT THIS HACKER! Read on.....  pcguy777 | 09/22/08
The defense against googlers getting your security answers  lipscombr@... | 09/24/08
Respect and integrity of our laws  terry@... | 10/08/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here