D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] (no subject)

 

On Tue, Apr 3, 2012 at 6:22 PM, badapple wrote:
> I will get to the bottom of this though, and will let you know if I can
> find a definitive answer. Thank god it wasn't my gmail or private
> account though, yahoo must have been the low hanging fruit I guess.

I'd be interested to learn what you find. I find it frustrating how
little we (the security community/industry) really know about why
webmail accounts get compromised.

One thing though: the password compromise, assuming it's that, doesn't
have to have happened very recently. Access to webmail accounts is
sold on the underground market per 1000 and the passwords may have
been stolen weeks ago.

Martijn.

-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq