On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

October 6th, 2009

Weak passwords dominate statistics for Hotmail's phishing scheme leak

Posted by Dancho Danchev @ 11:35 am

Categories: Browsers, Data theft, Hackers, Microsoft, Passwords, Phishing, Spam and Phishing

Tags: MSN Hotmail, Password, Phishing, Security, Spam And Phishing, Dancho Danchev

The recently leaked accounting data of thousands of Hotmail users — Gmail has also been affected — obtained through what appears to be a badly executed phishing campaign, once again puts the spotlight on the how bad password management practices remain an inseparable part of the user-friendly ecosystem.

According to a statistical analysis of the 10,000 passwords published by Bogdan Calin at Acunetix, 42% of the phished users use lower alpha passwords only (a to z), 19% rely on numbers only, with 22% of the total sampled population using a 6 character password (Live.com’s minimum), followed by 21% of users using 8 character passwords.

Here are the top 10 most commonly used passwords:

- 123456 - 64
- 123456789 - 18
- alejandra - 11
- 111111 - 10
- alberto - 9
- tequiero - 9
- alejandro - 9
- 12345678 - 9
- 1234567 - 8
- estrella - 7

And whereas brute-forcing email accounts on a mass scale has been replaced by the much more efficient and automated approach of registering new accounts, the weak password management practices used by the affected users combined with the fact that users continue using the same password across different services, can create a favorable chain reaction for a cybercriminal knowing this simple fact.

Does the size and complexity of a password matter in the case of online brute-forcing? It depends, in the sense that if the end user believes he’s visiting the legitimate site, not even a 15 character password will prevent a phisher from obtaining it, even worse if the end user is malware-infected, the cybercriminal wouldn’t even bother launching a phishing campaign at the first place. What he shouldn’t be able to do that easily through phishing, is obtain access to all the services in use by the phished user relying on a single password.

Despite the fact that Hotmail allows users the option to set a password to expire every 72 days, isn’t it time that Microsoft empowers its users with a Gmail-like “recent account activity” feature?

What do you think? Talkback.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 53 Talkback(s)
Um..
..what, exactly, would stop the phishing site from
passing the PNG on through to the user? (Read the rest)
Posted by: AzuMao Posted on: 10/29/09 You are currently: a Guest | | Terms of Use
Weak Passwords suck  bobiroc | 10/06/09
COMPARE PHISHING TO BURGLARY  JOHN_TUOHY | 10/08/09
I know it's not feasible ...  bjbrock | 10/06/09
Google and Hotmail are spyware  jorjitop | 10/06/09
Do you even know what phishing is? This isn't Gmail's or Hotmail's fault.  AzuMao | 10/07/09
Article confuses the issue  8string | 10/07/09
They Tend to Do that  mejohnsn | 10/09/09
That's starting to happen  d.s.williams | 10/13/09
Starting?  AzuMao | 10/29/09
Only if you let it be  mudfoot | 10/29/09
disallow weak passwords . . .  CobraA1 | 10/06/09
Re: disallow weak passwords  BethJones,SophosLabs | 10/07/09
People who use weak passwords  chrome_slinky@... | 10/06/09
Hear! Hear!  fjpoblam | 10/07/09
What makes you think  honeymonster | 10/07/09
2-factor authentication?  iTeaBoy | 10/07/09
Sounds good  d.s.williams | 10/09/09
Do you Know what 2 Factor Means?  mejohnsn | 10/09/09
Um..  AzuMao | 10/29/09
RE: Weak passwords dominate statistics for Hotmail's phishing scheme leak  mikin | 10/07/09
RE: Weak passwords dominate statistics for Hotmail's phishing scheme leak  Aboleyn | 10/07/09
As Long as There is Social Engineering, Passwords Will be Irrelevant.  GeneBuettner | 10/07/09
You are WRONG  mejohnsn | 10/09/09
RE: Weak passwords dominate statistics for Hotmail's phishing scheme leak  CzarCar | 10/07/09
Disallow stupid users?  Timpraetor | 10/07/09
WTH?  LiLac22281 | 10/07/09
Actually, yes!  tkepner | 10/07/09
How about this one?  AzuMao | 10/07/09
warm fuzzy feeling  Agnostic_OS | 10/10/09
Sorry for the confusion  Timpraetor | 10/09/09
confusion  LiLac22281 | 10/09/09
WTH?  Agnostic_OS | 10/10/09
Send it to  AzuMao | 10/10/09
Showing recent activity can be a big help!  llamasaki | 10/07/09
Spanish Passwords?  LiLac22281 | 10/07/09
Spanish Passwords  LiLac22281 | 10/07/09
What's the problem with weak passwords?  jonrichco | 10/07/09
Too many logins guys  Ondrax | 10/07/09
Fair point, BUT  d.s.williams | 10/09/09
That's not an argument in favor of weak passwords. It's an argument against  AzuMao | 10/09/09
RE: Weak passwords dominate statistics for Hotmail's phishing scheme leak  wooley | 10/08/09
Why shouldn't we?  AzuMao | 10/10/09
RE: Weak passwords dominate statistics for Hotmail's phishing scheme leak  modru | 10/08/09
Great idea. Replace passwords based on the alphabet with passwords based on  AzuMao | 10/08/09
Please explain  d.s.williams | 10/09/09
That the thing he linked to is useless.  AzuMao | 10/09/09
A bunch of pictures?  d.s.williams | 10/13/09
I'm pretty sure you can't.  AzuMao | 10/13/09
RE: Weak passwords dominate statistics for Hotmail's phishing scheme leak  bob_e_y | 10/08/09
Um? Difficult how?  AzuMao | 10/10/09
RE: Weak passwords dominate statistics for Hotmail's phishing scheme leak  dtrivison@... | 10/08/09
Strong passwords are as bad as weak passwords  d.s.williams | 10/09/09
what we need...  modru | 10/14/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads