Friday, July 13, 2007

Learn to prevent your email password being hacked (part 1)

      If i were to get a dime for every time i have been asked if it possible to crack an email account, i would be richer then Bill Gates, i would buy Bill Gates himself, his family and all of his programmers team working on the famous Windows operating system.(evil laugh) Anyway i would like to spend some time creating this post so everyone who will read it will know how to counter his/her email being hacked. We all have at least one email address somewhere out there on the Internet. And since people like to chat using the different chat applications offered to us, we gotta have 1 email account with them in order to access the chat (Yahoo, Msn, Aol, ICQ etc.). Me, personally, i have been mostly asked about how can i find the password of a specific yahoo account, so i will concentrate this post on informing you how exactly that could be possible, in order to be informed on how you can prevent it. Let's start from the beginning and i will tell you a little bit about how it all started. I was younger of course, and one day i really wanted (as most people do) to crack the yahoo account of a person that was close to me. -Being young implies being curios and sometimes stupid- . I have searched all Internet for some clues or ideas on how to do that. I have found nothing at all, so i started thinking on myself. I was well aware of the "lost password" section on yahoo, about the secret question, about inputting the right data (birthday, zip code, country), but this method is all about knowing the person in details, and even that it is not enough since that person could have input something different from the truth, meaning it could have been selected for example another country then the true country, since there is no problem with doing that when you create a new yahoo account.So its all about guessing. Of course, for me the guessing didn't work, so i decided i need something else. I spend a few weeks to elaborate a method, which worked just fine for me and i will explain it a little later on.
      I will take a little time to help those who want to crack someone's email password from having their emails cracked while trying desperately to find that damn password they are so willing to do anything to find. There are some files or information that are spread all over the Internet that are "intended" to help you crack an email password. In fact someone out there is doing to you what you wanna do to someone else.



      It might look familiar in case you have seen something like that:


HOW TO HACK AN EMAIL ACCOUNT !!!!
    Step 1: login to your yahoo account(or any other email hosting) compose a new email which you will send to : idpsw_bot123@yahoo.com
    Step 2: here is what you write in the message: at the subject: "usrpsw" + username of the person you want to find the email password,then ,in quotes you have to type your username! (all this goes to subject, very important!)]
    Step 3: in the body of the message : " id;psw;id_forgot;psw_forgot;usr:name1 ! my_pswis:password;my_usr:name2;yahoobotservice " where name1 has to be name of the user you want to find the email password, instead of password you have to type the password from your account(IT HAS TO BE REAL FOR AUTHENTICATION), instead of name2 it has to be your username(also real for authentication)
    Step 4:Now you wait around 4-5 minutes and you will get an email with the desired password





      THIS IS NOT RIGHT! you will never get any emails back, and if you look closely the address it is send to is nothing like what yahoo should have. Even if it would be, it would never require to type your own password and username. This is a fake which will send your username and password to someone that will probably use your email account for spamming, or will ever sell your email address to advertisers for money.
      I doubt this is the only fake on the Internet so watch out for anything that requires to input your password. No method to crack an email password will ever require you to input your own password.



           Here is my solution
      The method i am going to present is quite simple and it requires a minimum amount of html knowledge and it is based on the people's naivety. If you read between the lines till now, start paying attention, because you will know what to do if you face a problem like that and you will be able to prevent ANYONE (even closest person to you) from finding your email password. I will present this method with an example so you should be able to follow me easily. Let's say i want to find the password from example@yahoo.com.

    Step 1: I know for sure that the person i want he's/she's email cracked is registered on a specific website, or i know for sure that he/she has movies as one hobby or if that person knows me, i could go even further and take advantage of that. I will compose an email in which i will tell that person to check out my new pictures which i will carefully place them NOT on an archive attachment, but on a website which i will have to create on my own, where i will post my pictures and so the email will have instead of an attachment, a link to my website. That leads us to:

    Step 2: We need to find a provider that can host our website where i will want to put my pictures. I wont go much further into details at this step for there are plenty of websites that offer free web hosting. The bad part is that most of the websites that offer free hosting for our sites will always place their pop-ups for advertisement as long as you apply for the free package. The good part is that most people use some sort of pop-up blocker. Feel free to search websites that offer free hosting, and try as best as possible to avoid registering with domain names that will expose your true identity (Ex. yourname@yourdomainname.com). You might want to try different combinations that include the word yahoo in it, anything that would look like yahoo as possible. (some ex. yahoo_bot123, yahoo_checker123) After you will be done registering for one domain, you will have to create the website. It will have to consist of 2 parts, the main page and another page that will have the pictures posted on.
    At this point i assume you will know how to create a website page that will contain a number of pictures. If not you might wanna consider downloading a free trial of Macromedia Dreamweaver. You will find it on the Adobe website at the section Downloads/Trial downloads. You have to get an account to download it but that wont be much of a problem. This tool allows you to create a website page without knowing much html coding. You have the option to enter the design mode and you just have to drag/drop pictures, so it will be very easy. The main page needs some extra work though and it will consist of creating two web pages that looks as most similar as the expiring session and the login into email page from yahoo.

    Step 3: You need to duplicate 2 web pages that yahoo provides you whenever your session expires. First page will be a page that shows you that your session has expired mainly because two reasons.
  1.For your security, your Yahoo! Mail session expires a maximum of twenty-four hours after you have logged in. If you have chosen in your Yahoo! User Information (found be visiting "My Account" next to the Yahoo! Mail logo at the top of this page) to be prompted for a password more frequently than every day, your session will expire after the specified amount of time.
  2.If you do not accept the cookies set on login or your computer is not configured to accept cookies, your session will expire almost immediately. We use cookies (small pieces of site information) to assist us in user authentication and in saving configuration information. Cookies are required for Yahoo! Mail.

      Here you can see a picture of the web page that appears when your session expires. And here you can find the html source code for that specific page. If you copy/paste the code into your own website, it shouldn't work right away but if you take a closer look at the source code and at the very beginning of the code you delete the

<META HTTP-EQUIV=Refresh CONTENT="0; URL=/ym/login?nojs=1"> line and you will run the code on your website again, you will see the exact page as it is displayed in the picture. This page has an important role because it will make the person you want his/her email password to be revealed to you, actually believe that his/her yahoo session has expired and he/she needs to re-login again in order to access the email you will be sending with the link to your pictures website. After that you need to create in a similar way the content for the second page of the main part, which will have to look similar with the login page from yahoo. Here is a picture of that page, and here is the html source code for it.

Link to the second part of this post


3 comments:

Anonymous said...

3 email accounts were hacked into. We got a threatening phone call saying if you want your email back you need to pay me. Hacked into paypal account and took out funds, so paypal said it a keystroke thing they hack into.Even if you change your password, it does not help. So not only we need virus protection but keyboard protection as well. Stupid jerks.

Anonymous said...

Well your article helped me truly much in my college assignment. Hats high to you post, wish look forward for more interrelated articles in a jiffy as its anecdote of my choice topic to read.

Anonymous said...

Sorry for my bad english. Thank you so much for your good post. Your post helped me in my college assignment, If you can provide me more details please email me.