<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Hotmail hacked?&#x27; in forum &#x27;Scam and Phishbusters&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Hotmail-hacked-22395741</link>
<description></description>
<language>en</language>
<pubDate>Thu, 09 Feb 2012 20:48:29 EDT</pubDate>
<lastBuildDate>Thu, 09 Feb 2012 20:48:29 EDT</lastBuildDate>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22620624</link>
<description><![CDATA[anon posted : I don't think it would be too much effort for the hotmail servers to filter out anything going into or from a particualr site once it's confirmed that the site is going through illegitamate means and spamming (or is it more difficult than I think?).<br><br>I wonder as users  if there's anything we can do to return the favour and spam that particular website or somehow bring it down. <br><br>-Allan]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22620624</guid>
<pubDate>Sat, 27 Jun 2009 13:48:58 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22603414</link>
<description><![CDATA[Oleg posted : Never click links or open e-mails from sender you don't know.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22603414</guid>
<pubDate>Wed, 24 Jun 2009 14:09:04 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22602701</link>
<description><![CDATA[Bootboiler posted : Below is a header from one last night, on my honey's computer, it sent a copy to her, this is the header from that. email addresses are modified. pw was easy, 9 char, two words that go together, like blackbear.<br><br>X-Message-Delivery: Vj0xLjE7dXM9MDtsPTE7YT0wO0Q9MDtTQ0w9NA==<br>X-Message-Status: n:0<br>X-SID-PRA: Sue Heydt<br>X-SID-Result: Pass<br>X-Message-Info: jXuon5/YRm7j6Wz7om5I0k16g1jYmgsHoDxodSuOyCjR+sih+02LOegNdHHqmB8i6N99mMKaZ+m/IznqGFxsKJVEGEfRxaDh<br>Received: from bay0-omc2-s37.bay0.hotmail.com ([65.54.246.173]) by bay0-imc1-s17.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.2444);<br>Tue, 23 Jun 2009 19:47:34 -0700<br>Received: from BAY101-W3 ([64.4.56.103]) by bay0-omc2-s37.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959);<br>Tue, 23 Jun 2009 19:47:24 -0700<br>Message-ID:<br>Return-Path: su####er@hotmail.com<br>Content-Type: multipart/alternative;<br>boundary="_3dacc8f9-3e70-43e4-a5e5-d53b87b993f4_"<br>X-Originating-IP: [123.123.130.26]<br>From: Sue Heydt<br>Subject: RE:hi<br>Date: Wed, 24 Jun 2009 02:47:23 +0000<br>Importance: Normal<br>MIME-Version: 1.0<br>Bcc:<br>X-OriginalArrivalTime: 24 Jun 2009 02:47:24.0161 (UTC) FILETIME=[1A511710:01C9F476]<br><br>--_3dacc8f9-3e70-43e4-a5e5-d53b87b993f4_<br>Content-Type: text/plain; charset="ks_c_5601-1987"<br>Content-Transfer-Encoding: 8bit<br><br>Dear potential partner,<br>Do you need famous brand of electronic products with original quality and international warranty? Do you want to start your own business career for money making ?<br>What ever you are a small personal business or largest wholesale entity we also can provide your support to be our stable customers or agent.<br>We are largest wholesale business on consumming electronic products between America&China, laptops, Digital camera Videos,GPS,cellphone,mp4,game console and many other electronic products.which market is mainly in Europe,America,south Asia,Australia and Southen America.<br>There is much profit for you if you are our stable customer or agent.<br>For more information please contact as bellow :<br>Address&pound;&ordm;N0.15,Haidian District shangdi information road Beijing ,China<br>Tel(Fax)&pound;&ordm;+861081836757<br>phone: +8615101621070<br>MSN&pound;&ordm;sangefa-vip@hotmail.com<br>E-mail: sangefa@188.com<br>WEB : www.sangefa.com]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22602701</guid>
<pubDate>Wed, 24 Jun 2009 12:02:12 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22602676</link>
<description><![CDATA[anon posted : Below is a header from one last night, on my honey's computer, it sent a copy to her, this is the header from that.  email addresses are modified.  pw was easy, 9 char, two words that go together, like blackbear.<br><br>X-Message-Delivery: Vj0xLjE7dXM9MDtsPTE7YT0wO0Q9MDtTQ0w9NA==<br>X-Message-Status: n:0<br>X-SID-PRA: Sue Heydt <br>X-SID-Result: Pass<br>X-Message-Info: jXuon5/YRm7j6Wz7om5I0k16g1jYmgsHoDxodSuOyCjR+sih+02LOegNdHHqmB8i6N99mMKaZ+m/IznqGFxsKJVEGEfRxaDh<br>Received: from bay0-omc2-s37.bay0.hotmail.com ([65.54.246.173]) by bay0-imc1-s17.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.2444);<br>&#9; Tue, 23 Jun 2009 19:47:34 -0700<br>Received: from BAY101-W3 ([64.4.56.103]) by bay0-omc2-s37.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959);<br>&#9; Tue, 23 Jun 2009 19:47:24 -0700<br>Message-ID: <br>Return-Path: su####er@hotmail.com<br>Content-Type: multipart/alternative;<br>&#9;boundary="_3dacc8f9-3e70-43e4-a5e5-d53b87b993f4_"<br>X-Originating-IP: [123.123.130.26]<br>From: Sue Heydt <br>Subject: RE:hi<br>Date: Wed, 24 Jun 2009 02:47:23 +0000<br>Importance: Normal<br>MIME-Version: 1.0<br>Bcc:<br>X-OriginalArrivalTime: 24 Jun 2009 02:47:24.0161 (UTC) FILETIME=[1A511710:01C9F476]<br><br>--_3dacc8f9-3e70-43e4-a5e5-d53b87b993f4_<br>Content-Type: text/plain; charset="ks_c_5601-1987"<br>Content-Transfer-Encoding: 8bit<br><br>Dear potential partner,<br>Do you need famous brand of electronic products with original quality and international warranty? Do you want to start your own business career for money making ? <br>What ever you are a small personal business or largest wholesale entity we also can provide your support to be our stable customers or agent.<br>We are largest wholesale business on consumming electronic products between America&China, laptops, Digital camera Videos,GPS,cellphone,mp4,game console and many other electronic products.which market is mainly in Europe,America,south Asia,Australia and Southen America.<br>There is much profit for you if you are our stable customer or agent.<br>For more information please contact as bellow :  <br>Address&pound;&ordm;N0.15,Haidian District shangdi information road Beijing ,China<br>Tel(Fax)&pound;&ordm;+861081836757<br>phone: +8615101621070<br>MSN&pound;&ordm;sangefa-vip@hotmail.com<br>E-mail: sangefa@188.com<br>WEB :  www.sangefa.com]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22602676</guid>
<pubDate>Wed, 24 Jun 2009 11:57:58 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22542764</link>
<description><![CDATA[MGD posted : <div class="bquote"><small>said by <a href="/profile/314530" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=314530');">NormanS</a>:</small><br><br><div class="bquote"><small>said by <a href="/profile/666842" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=666842');">MGD</a>:</small><br><br><b>Microsoft SMTPSVC(6.0.3790.3959);</b><br><br>I am presuming that line above does not mean that it was a true SMTP, like from an smtp client. My outbound hotmail sent via an SMTP client will not show in my "webmail" sent items. <br> </div>On the basis of the version number? Or the agent name?<br><br>Just curious why you might think that 'Microsoft SMTPSVC(x.x.xxxx.xxxx)' would not be a "true SMTP", like from an SMTP client?<br></div>Good catch, Now that you bring it up, I am curious why I made that statement too !. It is incorrect,  <br><i>'Microsoft SMTPSVC(x.x.xxxx.xxxx)'</i> will show up in the headers regardless of whether the email originates from within a local SMTP client or is sent via the webmail interface.<br><br>As you mentioned in another post mail sent via an SMTP client will not show in the sent items of the webmail interface.<br><br>Apparently in some cases the hackers are copying the victim's address book and then spamming via a n smtp application. I am not sure if some victims are reporting that the spam does show in their webmail sent items or not. What most do report is that their accounts are altered, either set in auto respond away mode  (with a copy of the spam) or a signature is added to include the spam which then appears in all subsequent outbound mail.<br><br>I am presuming based on the sheer volume of this epidemic, that this process may be somehow scripted by the scammers.<br><br>There is not a lot of feedback coming from the support people that identifies what the modus operandi is. I am sure they have to know by now. I do not believe that all the accounts are password cracked, nor do I believe that they are all phished. There is some other angle at work here.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22542764</guid>
<pubDate>Fri, 12 Jun 2009 19:24:24 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22537276</link>
<description><![CDATA[NormanS posted : <div class="bquote"><small>said by <a href="/profile/437017" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=437017');">TearAbite</a>:</small><br><br>After one of my wife's old hotmail accounts was sending out money requests to all of her contacts via Western Union for her "trip to nigera", i did some searching and found that it is indeed happening to a LOT of other people, beginning around January or so of this year.  <br> </div>Which is, coincidentally, about the time that Windows Live Hotmail began to reintroduce free POP3 access (which used to be allowed before Microsoft bought Hotmail).<br><br>And email sent via 'smtp.live.com' will not show up in the "Sent Items" folder of either the Web mail view, or the HTTPMail client.<br><small>--<br>Norman<br>~Oh Lord, why have you come<br>~To Konnyu, with the Lion and the Drum</small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22537276?c=1438472&ret=L2ZvcnVtL3IyMjM5NTc0MS54bWw%3D"><IMG TITLE="39393 bytes" BORDER=0 WIDTH=500 HEIGHT=249 SRC="/r0/download/1438472~c5062d83ac1ff0ce1e87291b2fbbc36e/Hotmail(001).JPG"></A><br>Showing email sent from Hotmail to another account.</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22537276?c=1438473&ret=L2ZvcnVtL3IyMjM5NTc0MS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="24211 bytes" WIDTH=600 HEIGHT=95 SRC="/r0/download/1438473.thumb600~2433ced18fc98ac431e15d58b448a176/Hotmail(000).JPG/thumb.jpg" ALT="Click for full size"></A><br>Showing the Windows Live Mail view of sent Hotmail.</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22537276?c=1438474&ret=L2ZvcnVtL3IyMjM5NTc0MS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="23564 bytes" WIDTH=600 HEIGHT=90 SRC="/r0/download/1438474.thumb600~4e23f3aa7e88618c4557517027d188a7/Hotmail(002).JPG/thumb.jpg" ALT="Click for full size"></A><br>Showing the Web view of sent Hotmail.</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22537276</guid>
<pubDate>Thu, 11 Jun 2009 21:23:56 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22536655</link>
<description><![CDATA[NormanS posted : <div class="bquote"><small>said by <a href="/profile/666842" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=666842');">MGD</a>:</small><br><br><b>Microsoft SMTPSVC(6.0.3790.3959);</b><br><br>I am presuming that line above does not mean that it was a true SMTP, like from an smtp client. My outbound hotmail sent via an SMTP client will not show in my "webmail" sent items. <br> </div>On the basis of the version number? Or the agent name?<br><pre class="brush: text">Return-path: &lt;troll.feeder@kook.invalid&gt;&#012;Received: from kozue.aosake.net (192.168.102.34) by aosake.net (Mercury/32 v4.62) with ESMTP ID MG00004E;&#012;   11 Jun 2009 16:07:28 -0700&#012;Received: from KOZUE (&#91;192.168.102.34&#93;) by kozue.aosake.net with Microsoft SMTPSVC(6.0.2600.5512);&#012; Thu, 11 Jun 2009 16:07:28 -0700&#012;From: "Morris R. ze Kat" &lt;spammers_r@stupid.invalid&gt;&#012;Subject: &#91;TEST&#93; Didn't work?&#012;To: ******@aosake.net&#012;User-Agent: 40tude_Dialog/2.0.15.41&#012;MIME-Version: 1.0&#012;Content-Type: text/plain; charset="us-ascii"&#012;Content-Transfer-Encoding: 7bit&#012;Sender: troll.feeder@kook.invalid&#012;Organization: Kookville&#012;Date: Thu, 11 Jun 2009 16:07:28 -0700&#012;Message-ID: &lt;1s78jfw12si6d$.dlg@kat.dizum.com&gt;&#012;X-Approved-By: The Other Guy&#012;X-OriginalArrivalTime: 11 Jun 2009 23:07:28.0140 (UTC) FILETIME=&#91;63EB14C0:01C9EAE9&#93;&#012; &#012;</pre><!--end code block-->Just curious why you might think that 'Microsoft SMTPSVC(x.x.xxxx.xxxx)' would not be a "true SMTP", like from an SMTP client?<br><br><small>--<br>Norman<br>~Oh Lord, why have you come<br>~To Konnyu, with the Lion and the Drum</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22536655</guid>
<pubDate>Thu, 11 Jun 2009 19:15:37 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22407299</link>
<description><![CDATA[madylarian posted : <div class="bquote"><small>said by <a href="/profile/766601" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=766601');">AVD</a>:</small><br><br>Do you use facebook or skype or other social networking service that looks at your contact list to match up other potential users? <br> </div>I do have MySpace and Facebook pages but there is no connection as I neither used the Hotmail address for them nor even allowed access to any contact lists or addressbooks.<br><br>mady<br><small>--<br>Honi soit qui mal y pense</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22407299</guid>
<pubDate>Mon, 18 May 2009 16:56:27 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22405728</link>
<description><![CDATA[AVD posted : Do you use facebook or skype or other social networking service that looks at your contact list to match up other potential users? ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22405728</guid>
<pubDate>Mon, 18 May 2009 11:52:44 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22397205</link>
<description><![CDATA[MGD posted : <div class="bquote"><small>said by <a href="/profile/795407" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=795407');">Snowy</a>:</small><br><br><div class="bquote"><small>said by <a href="/profile/666842" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=666842');">MGD</a>:</small><br><br>I presume they are using some script,...<br> </div>Absolutely.<br>re 4 random letters combined with 4 random numbers isn't a hacker friendly combination by anyone's standards so my guess is it's not a mini brute force happening.<br><br>EDIT to add: it's always nice to be agree with but there's a lot more profit to made with that type of processing power than hacking hotmail accounts.<br>I was expecting to see a PW something like "letmeinnow!" ;)<br> </div>Agree, that is millions of combinations for one account, not a productive method. If they are not all phished then maybe this direction: &raquo;<A HREF="http://www.google.com/search?hl=en&q=hacking+hotmail+exploits&aq=f&oq=" >www.google.com/search?hl=en&q=ha&middot;&middot;&middot;aq=f&oq=</A><br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22397205</guid>
<pubDate>Sat, 16 May 2009 01:27:41 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22397199</link>
<description><![CDATA[madylarian posted : <div class="bquote"><small>said by <a href="/profile/666842" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=666842');">MGD</a>:</small><br><br>Interesting...<br><br>Do you routinely stay logged in to MSN while browsing the web, or is it set to auto log in. I am wondering how the MSN session id cookie behaves. </div>I only check Hotmail (and my other junk accounts) once a day.  I close the window but I don't log out.  However I did let Firefox save the password, so I am not sure if that is what you mean about auto log in.  That is, when I go back the next day I don't have to log on again.  Is that what you mean?<br><br>mady<br><small>--<br>Honi soit qui mal y pense</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22397199</guid>
<pubDate>Sat, 16 May 2009 01:25:37 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22397171</link>
<description><![CDATA[Snowy posted : <div class="bquote"><small>said by <a href="/profile/666842" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=666842');">MGD</a>:</small><br><br>I presume they are using some script,...<br> </div>Absolutely.<br>re 4 random letters combined with 4 random numbers isn't a hacker friendly combination by anyone's standards so my guess is it's not a mini brute force happening.<br><br>EDIT to add: it's always nice to be agree with but there's a lot more profit to made with that type of processing power than hacking hotmail accounts.<br>I was expecting to see a PW something like "letmeinnow!" ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22397171</guid>
<pubDate>Sat, 16 May 2009 01:12:38 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22397167</link>
<description><![CDATA[MGD posted : Interesting...<br><br>Do you routinely stay logged in to MSN while browsing the web, or is it set to auto log in. I am wondering how the MSN session id cookie behaves.<br><br>I know in the past a proof of concept with Gmail for example allowed a session login cookie to be hijacked and then used from another IP, though it was a complex process, that would appear to be way above this skill level.<br><br>I like  Snowy <A HREF="/useremail/u/795407"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>'s potential scenario, there is an abundant supply of cheap labor There could be thousands gainfully employed testing pws 21/7.<br><br>124.135.246.67 does not show up on any listings, so I assume they are not spewing from that IP. Not a ptr on any IP in the route as soon as you hot the mainland:<br><br>[att=1] <br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22397167?c=1429537&ret=L2ZvcnVtL3IyMjM5NTc0MS54bWw%3D"><IMG TITLE="64963 bytes" BORDER=0 WIDTH=556 HEIGHT=419 SRC="/r0/download/1429537~c8242b60f7a0aaf813fe7594e06ec0fc/china_IP_trace.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22397167</guid>
<pubDate>Sat, 16 May 2009 01:10:27 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22397132</link>
<description><![CDATA[madylarian posted : MGD:  They may not have sent it from my account but they sent it to the first 5 people on my contact list.  I did send the headers to abuse@hotmail but I am not holding my breath for an answer.  I have a feeling that the answer to your other questions is in the <A HREF="http://windowslivehelp.com/community/">WindowsLive Help Forums</a>, if you want to wade through them.<br><br>mady<br><small>--<br>Honi soit qui mal y pense</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22397132</guid>
<pubDate>Sat, 16 May 2009 00:59:47 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22397129</link>
<description><![CDATA[MGD posted : <div class="bquote"><small>said by <a href="/profile/795407" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=795407');">Snowy</a>:</small><br><br>Your account was accessed from China which is not a surprise.<br>Since you've been able to change it, what was the hacked password?<br>IM works too.<br> </div>I presume they are using some script, otherwise even if they were paying all those laid off Chineese workers to manually log in to every ones account, then it would still show up in the sent folder, if a webmail log in was used. <br><br><b>Microsoft SMTPSVC(6.0.3790.3959);</b><br><br>I am presuming that line above does not mean that it was a true SMTP, like from an smtp client. My outbound hotmail sent via an SMTP client will not show in my "webmail" sent items. However in  madylarian <A HREF="/useremail/u/553533"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>'s case they had to at least log in via webmail in order to hijack her address book.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22397129</guid>
<pubDate>Sat, 16 May 2009 00:58:32 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22397115</link>
<description><![CDATA[madylarian posted : The password was 4 letters plus 4 numbers.  The letters didn't spell anything, were not scrambled letters of a word, not in alpha order and not in any proximity on a keyboard.  The numbers also were not in any particular order.<br><br>mady<br><small>--<br>Honi soit qui mal y pense</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22397115</guid>
<pubDate>Sat, 16 May 2009 00:52:29 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22397114</link>
<description><![CDATA[MGD posted : Interesting, it appears in that case that the original mail did not originate from your machine. Rather from an IP in China. X-Originating-IP: [124.135.246.67]<br><br>IP 124.135.246.67<br>route:        124.128.0.0/13<br>descr:        CNC Group CHINA169 Shandong Province Network<br>country:      CN<br>origin:       AS4837<br>mnt-by:       MAINT-CNCGROUP-RR<br>changed:      abuse@cnc-noc.net 20060306<br>source:       APNIC<br><br>person:       ChinaUnicom Hostmaster<br>nic-hdl:      CH1302-AP<br>e-mail:       abuse@chinaunicom.cn<br>address:      No.21,Jin-Rong Street<br>address:      Beijing,100140<br>address:      P.R.China<br>phone:        +86-10-82993155<br>fax-no:       +86-10-82993144<br>country:      CN<br>changed:      abuse@chinaunicom.cn 20090408<br>mnt-by:       MAINT-CNCGROUP<br>source:       APNIC<br><br>person:       Data Communication Bureau Shandong<br>nic-hdl:      DS95-AP<br>e-mail:       ip@sdinfo.net<br>address:      No.77 Jingsan Road,Jinan,Shandong,P.R.China<br>phone:        +86-531-6052611<br>fax-no:       +86-531-6052414<br>country:      CN<br>changed:      ip@sdinfo.net 20050330<br>mnt-by:       MAINT-CNCGROUP-SD<br>source:       APNIC<br><br>However I like to see the "X-Originating-IP" show up again in the first received line. This would be preferable, where the X-originating also repeats in the first line:<br><br> <blockquote><small>quote:</small><hr>...<br>..<br>Received: from 111.111.111.111 by BAY105-DAV11.phx.gbl with DAV;<br>&#9;Fri, 01 May 2009 13:58:56 +0000<br>X-Originating-IP: [111.111.111.111]<br>X-Originating-Email: [anyname@hotmail.com]<br>X-Sender: anyname@hotmail.com<br><hr></blockquote><br><br>Though in your case the foreign originating IP is substantiated by the fact that the mail is not in your sent box, which it would not be if it originated from IP 124.135.246.67 and was also sent sent via a script and not by going through an actual webmail login. So in your case your account credentials were used fom an IP in CHINA.<br><br>I wonder if there are other victims who do see the spam in sent items, or if they are all just reporting bounces.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22397114</guid>
<pubDate>Sat, 16 May 2009 00:52:17 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22397077</link>
<description><![CDATA[Snowy posted : Your account was accessed from China which is not a surprise.<br>Since you've been able to change it, what was the hacked password?<br>IM works too.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22397077</guid>
<pubDate>Sat, 16 May 2009 00:37:29 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22397039</link>
<description><![CDATA[madylarian posted : MGD:  I was finally able to change my password.  I guess I should have known that Hotmail doesn't play nice with Firefox.<br><br>To answer your other questions, I did see those other threads and there was nothing in my sent folder, no signature (I don't think I ever made one), no vacation response, and no embedded spamvertising other than that added by Hotmail.<br><br>And, as a matter of fact, I DO have one of the emails, including headers, from someone in my contact list.  They are the person who told me this had happened.  I'll post the headers below, but with email addresses redacted.  FYI, I am on Comcast as is the recipient of this spam.<br><br><blockquote><br>Microsoft Mail Internet Headers Version 2.0<br>Received: from PAOAKEXCSMTP01.cable.comcast.com ([10.52.116.30]) by<br>NJCHLEXCMB01.cable.comcast.com with Microsoft SMTPSVC(6.0.3790.3959);<br>&#9; Fri, 8 May 2009 03:18:13 -0400<br>Received: from PACDCEXCSMTP04.cable.comcast.com ([24.40.15.118]) by<br>PAOAKEXCSMTP01.cable.comcast.com with Microsoft SMTPSVC(6.0.3790.3959);<br>&#9; Fri, 8 May 2009 03:18:13 -0400<br>Received: from cable.comcast.com ([24.40.8.136]) by<br>PACDCEXCSMTP04.cable.comcast.com with Microsoft SMTPSVC(6.0.3790.3959);<br>&#9; Fri, 8 May 2009 03:18:13 -0400<br>Received: from ([24.40.8.143])<br>&#9;by pacdcimi02.cable.comcast.com with ESMTP  id 5503616.48522706;<br>&#9;Fri, 08 May 2009 03:17:49 -0400<br>Received: from ([65.54.246.76])<br>&#9;by pacdcedge01.cable.comcast.com with ESMTP  id 5302275.EDGE;<br>&#9;Fri, 08 May 2009 03:17:48 -0400<br>Received: from BAY133-W11 ([65.55.138.46]) by bay0-omc1-s4.bay0.hotmail.com <br>with<br>Microsoft SMTPSVC(6.0.3790.3959);<br>&#9; Fri, 8 May 2009 00:17:48 -0700<br>Message-ID: <br>Return-Path: xxxxxx@hotmail.com<br>Content-Type: multipart/alternative;<br>&#9;boundary="_7480779a-6962-42dd-a54b-9ca742508180_"<br>X-Originating-IP: [124.135.246.67]<br>From: <br>To: , , ,<br>&#9; , ,<br>&#9;, <br>Subject: hi<br>Date: Fri, 8 May 2009 03:17:48 -0400<br>Importance: Normal<br>MIME-Version: 1.0<br>X-OriginalArrivalTime: 08 May 2009 07:17:48.0948 (UTC)<br>FILETIME=[17A0DD40:01C9CFAD]<br>X-esp: ESP=<br>&#9;SHA: <br>&#9;UHA: <br>&#9;BAYES: <br>&#9;SenderID: <br>&#9;DKIM: <br>&#9;TS: <br>&#9;SIG:<br>&#9;DSC: <br>&#9;TRU_embedded_image_spam: <br>&#9;TRU_phish_spam: <br>&#9;TRU_money_spam: <br>&#9;TRU_marketing_spam: <br>&#9;TRU_spam2: <br>&#9;TRU_medical_spam: <br>&#9;TRU_ru_spamsubj: <br>&#9;TRU_misc_spam: <br>&#9;TRU_adult_spam: <br>&#9;TRU_profanity_spam: <br>&#9;TRU_freehosting: <br>&#9;TRU_lotto_spam: <br>&#9;TRU_watch_spam: <br>&#9;TRU_urllinks: <br>&#9;TRU_scam_spam: <br>&#9;TRU_html_image_spam: <br>&#9;TRU_spam1: <br>&#9;TRU_playsites: <br>&#9;TRU_legal_spam: <br>&#9;URL Real-Time Signatures: <br>&#9;TRU_stock_spam: <br><br>--_7480779a-6962-42dd-a54b-9ca742508180_<br>Content-Type: text/plain; charset="iso-8859-1"<br>Content-Transfer-Encoding: quoted-printable<br><br>--_7480779a-6962-42dd-a54b-9ca742508180_<br>Content-Type: text/html; charset="iso-8859-1"<br>Content-Transfer-Encoding: quoted-printable<br><br>--_7480779a-6962-42dd-a54b-9ca742508180_--<br></blockquote><br><br>mady<br><small>--<br>Honi soit qui mal y pense</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22397039</guid>
<pubDate>Sat, 16 May 2009 00:22:15 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22397023</link>
<description><![CDATA[MGD posted : Yes, they could run consecutive scripts after a wait time from multiple IPs and over time go through a load of passwords. I am not sure what the account lock out settings are for Hotmail. <br><br>They can also accrue the contacts in each account to provide a never ending pool of addresses.  nwrickert <A HREF="/useremail/u/1070900"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>'s phishing scenario is also valid, as I am sure they are not limiting themselves to a single vector. The issue for Live Help though is that there are such a wide range of victims that their error is just assuming that every compromised account report equals a victim who was conned out of their password or has an infected machine.<br><br>Many of the reports also describe an after effect of a malfunctioning account. Presumably the operation of sending spam to batches of a half dozen addresses at a time, and the addition of a spam signature is also a scripted event.<br><br>Though there are a considerable amount of similar reports over a long period, I do not see any reports of the known method of compromise, or detailed analysis. Clearly though, the purpose is identical, and the accounts appear "borrowed".<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22397023</guid>
<pubDate>Sat, 16 May 2009 00:13:45 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22396947</link>
<description><![CDATA[Snowy posted : <div class="bquote"><small>said by <a href="/profile/666842" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=666842');">MGD</a>:</small><br><br> <br>There is something else at work here, and it may involve direct scripting exploits at their end, or insecure session cookies that can be hijacked.<br> </div>It could also be as fundamental as a common list of fairly uncommon passwords, or even common ones for that matter.<br>I suppose it wouldn't be too difficult to query a few hundred thousand hotmail accounts in a day using one less login attempt than would trigger an account lockout with hotmail, or anyone else.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22396947</guid>
<pubDate>Fri, 15 May 2009 23:49:18 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22396931</link>
<description><![CDATA[MGD posted : Selling knock off Apple products from China too, in 2008 many of these fake clones ended up on Ebay, all were useless junk.<br><br>Nice, anytime you see VISA and MASTERCARD logos alongside a WESTERN UNION logo, that means that they never accept credit card payments, only cash via WU. WU logos over rule all others, and will be the only form of payment accepted.<br><br>Lots of Flash, plus online chat, may not show up in siteshots:<br><br><div class="borderless siteshot"><small><A TITLE="Zoom" HREF="http://i.dslr.net/urls/20/90220.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/20/90220-big.gif" width=280 height=202></A><br>&raquo;<A HREF="http://Aebcc.com" >Aebcc.com</A><br>Snapped 2009-05-15 23:40:29 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br><div class="borderless siteshot"><small>[imaging failed]<br>&raquo;<A HREF="http://Aoa8.com" >Aoa8.com</A><br>Snapped 2009-05-15 23:40:11 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br><div class="borderless siteshot"><small><A TITLE="Zoom" HREF="http://i.dslr.net/urls/22/90222.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/22/90222-big.gif" width=280 height=202></A><br>&raquo;<A HREF="http://Aobcc.com" >Aobcc.com</A><br>Snapped 2009-05-15 23:40:10 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br><div class="borderless siteshot"><small><A TITLE="Zoom" HREF="http://i.dslr.net/urls/23/90223.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/23/90223-big.gif" width=280 height=202></A><br>&raquo;<A HREF="http://Aobcc.net" >Aobcc.net</A><br>Snapped 2009-05-15 23:39:51 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br><div class="borderless siteshot"><small><A TITLE="Zoom" HREF="http://i.dslr.net/urls/24/90224.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/24/90224-big.gif" width=280 height=202></A><br>&raquo;<A HREF="http://Buy-hot.com" >Buy-hot.com</A><br>Snapped 2009-05-15 23:39:29 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br><div class="borderless siteshot"><small><A TITLE="Zoom" HREF="http://i.dslr.net/urls/25/90225.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/25/90225-big.gif" width=280 height=202></A><br>&raquo;<A HREF="http://Buy-hot.net" >Buy-hot.net</A><br>Snapped 2009-05-15 23:39:09 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br><div class="borderless siteshot"><small><A TITLE="Zoom" HREF="http://i.dslr.net/urls/26/90226.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/26/90226-big.gif" width=280 height=202></A><br>&raquo;<A HREF="http://Elebc.com" >Elebc.com</A><br>Snapped 2009-05-15 23:38:46 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br><div class="borderless siteshot"><small><A TITLE="Zoom" HREF="http://i.dslr.net/urls/27/90227.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/27/90227-big.gif" width=280 height=202></A><br>&raquo;<A HREF="http://Malls-hot.com" >Malls-hot.com</A><br>Snapped 2009-05-15 23:38:26 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br><div class="borderless siteshot"><small><A TITLE="Zoom" HREF="http://i.dslr.net/urls/28/90228.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/28/90228-big.gif" width=280 height=202></A><br>&raquo;<A HREF="http://Sell-good.com" >Sell-good.com</A><br>Snapped 2009-05-15 23:38:07 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br><div class="borderless siteshot"><small>[imaging failed]<br>&raquo;<A HREF="http://Shopping333.com" >Shopping333.com</A><br>Snapped 2009-05-15 23:37:48 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br>EDIT=<br><br>Just about every search of any related domain name, or email address keyword brings up "someone is sending emails from my account" scattered over the last few months: &raquo;<A HREF="http://www.google.com/search?hl=en&q=aebcc@msn.com+&btnG=Google+Search&aq=f&oq=" >www.google.com/search?hl=en&q=ae&middot;&middot;&middot;aq=f&oq=</A><br><br>MGD<br><br>Results for 58.30.225.41 <br><br>01. Aebcc.com = SCAM FRAUD SPAMMERS FAKE PRODUCTS<br>02. Aoa8.com = SCAM FRAUD SPAMMERS FAKE PRODUCTS<br>03. Aobcc.com = SCAM FRAUD SPAMMERS FAKE PRODUCTS<br>04. Aobcc.net = SCAM FRAUD SPAMMERS FAKE PRODUCTS<br>05. Buy-hot.com = SCAM FRAUD SPAMMERS FAKE PRODUCTS<br>06. Buy-hot.net = SCAM FRAUD SPAMMERS FAKE PRODUCTS<br>07. Elebc.com = SCAM FRAUD SPAMMERS FAKE PRODUCTS<br>08. Malls-hot.com = SCAM FRAUD SPAMMERS FAKE PRODUCTS<br>09. Sell-good.com = SCAM FRAUD SPAMMERS FAKE PRODUCTS<br>10. Shopping333.com = SCAM FRAUD SPAMMERS FAKE PRODUCTS]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22396931</guid>
<pubDate>Fri, 15 May 2009 23:44:02 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22396842</link>
<description><![CDATA[MGD posted : <div class="bquote"><small>said by <a href="/profile/553533" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=553533');">madylarian</a>:</small><br><br>..... Hotmail has a problem and they seem to refuse to acknowledge it.<br><br>mady<br> </div>That identical issue has also been occurring with Yahoo accounts. Complaints about the Hotmail hijacking go back to at least the third quarter of 2008, with the identical scenario. The spam is always for domains registered in China, selling cheap counterfeit knock offs of everything from clothing to electronics.<br><br>You can see pages of reports of the identical spam with the same format of missing spaces in the text: &raquo;<A HREF="http://www.google.com/search?hl=en&q=%22Hello.How+are+you+doing+recently%3FSome+days+ago%2C+I+came+across+a+wonderful%22" >www.google.com/search?hl=en&q=%2&middot;&middot;&middot;erful%22</A><br><br>Without the forced quotations more are pulled in: &raquo;<A HREF="http://www.google.com/search?hl=en&q=Hello.How+are+you+doing+recently%3FSome+days+ago%2C+I+came+across+a+wonderful&btnG=Google+Search&aq=f&oq=" >www.google.com/search?hl=en&q=He&middot;&middot;&middot;aq=f&oq=</A> <br><br>I agree that it is most likely not a phishing issue, possibly related to session cookie hijacking, or some other flaw. The interesting fact is that many victims passwords are not changed, so I presume we can rule out some form of account resetting. Many victims also report that their account now contains an embedded signature of the spam that is sent along with every out bound mail that the victim subsequently processes.<br><br>I read you other forum post: &raquo;<A HREF="http://windowslivehelp.com/community/t/22022.aspx" >windowslivehelp.com/community/t/22022.aspx</A> and if I understand it correctly, your password was not changed, though you are unable to change it now? Also, you said that the outbound spam mail does not show in your sent items? You don't by chance have a copy from one of the people in your address book, so that you can see from the headers what the originating IP was.?<br><br>I believe that there was a recent report in this forum about the identical issue, maybe several posts.<br><br>Here is a report from that above Google link from circa 12/2008: &raquo;<A HREF="http://www.hisstank.com/forum/general-discussion/26739-someone-just-hacked-into-my-email-account.html" >www.hisstank.com/forum/general-d&middot;&middot;&middot;unt.html</A><br><br>I also think that there could be a scripting exploit on Hotmail's servers, see these peculiar reports for example: &raquo;<A HREF="http://scoundrelpublishing.com/spart/viewtopic.php?p=207230&sid=ba4a54f0a490d008611e0617c93a748d" >scoundrelpublishing.com/spart/vi&middot;&middot;&middot;c93a748d</A><br><br>All have the common modus operandi though, batches of out bound mail to address contacts, all spamming the same type of Chinese domains.<br><br>In fact the one you listed <b>sell-good.com</b> is hosted on a server in China with other domains that also show up in victim reports:<br><br>Search Results for 58.30.225.41 [no reverse DNS set]<br><br>10 Results for 58.30.225.41 (Sell-good.com) <br>  <br> Website <br><br>01.  Aebcc.com <br>02.  Aoa8.com  <br>03.  Aobcc.com <br>04.  Aobcc.net <br>05.  Buy-hot.com <br>06.  Buy-hot.net <br>07.  Elebc.com <br>08.  Malls-hot.com <br>09.  Sell-good.com <br>10.  Shopping333.com <br><br>Many seem to rotate between two DNS servers:<br><br>Sell-good.com <br><br>History:<br><br>2009-01-15 Transfer FROM  53dns.com TO 71one.com  <br>2009-04-22 Transfer FROM  71one.com TO 53dns.com <br><br>A check of sites using the 53dns is inconclusive:<br><br>&raquo;<A HREF="http://www.gwebtools.com/ns-spy/dns1.53dns.com" >www.gwebtools.com/ns-spy/dns1.53dns.com</A><br><br>Agree with  Snowy <A HREF="/useremail/u/795407"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> I think Hotmail is missing the ball with that boiler plate response. There is something else at work here, and it may involve direct scripting exploits at their end, or insecure session cookies that can be hijacked.<br><br>Live Help has been sprouting that same secure your account response since back in December of 2008: &raquo;<A HREF="http://windowslivehelp.com/community/p/1709/10024.aspx" >windowslivehelp.com/community/p/&middot;&middot;&middot;024.aspx</A> However there are enough reports from people who do not appear to have compromised PCs, or were phished. That earlier link has one victim who had all three of his hotmail accounts compromised simultaneoulsy.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22396842</guid>
<pubDate>Fri, 15 May 2009 23:19:07 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22396112</link>
<description><![CDATA[madylarian posted : <div class="bquote"><small>said by <a href="/profile/1070900" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1070900');">nwrickert</a>:</small><br><br><div class="bquote">It defies common sense that user side machines are being compromised for hotmail credentials.</div>We see phishing activity to get student and faculty authentication data, and then the compromised accounts are used for spamming.  It isn't the user machine being compromised in that case, but it also isn't the server being compromised.<br><br>I assume that the same kind of phishing activity goes on with hotmail, yahoo, gmail and similar services.<br> </div>These are not phishing emails.  So far all of the ones I've seen are the same as the one I got:<br><br><blockquote><br>Dear firend, <br>    Hello.How are you doing recently?Some days ago, I came across a wonderful<br>electronic company on the web and had a pleasant chat with the sales manager who<br>can offer various kinds of digital products,such as the phone s,  T V, noteboo<br>k, video, computers, Mp 4, GP S,PS 3, digital cameras and so on. He told me that<br>they are planning to lower the prices greatly in order to adapt to the global<br>economic crisis, so that they can expand their overseas market! I have bought  a<br>computer,and i am very satisfied with their items and services.If you have<br>time,you can have a look.<br>Their website:      sell-good.com<br><br>Their Email:     sellgood@188.com<br>Their Msn:      sell-good@msn.com<br></blockquote><br><br>Do a search on "sell-good.com", or check these:<br>&raquo;<A HREF="http://windowslivehelp.com/community/t/22022.aspx" >windowslivehelp.com/community/t/22022.aspx</A><br>&raquo;<A HREF="http://windowslivehelp.com/community/t/35178.aspx" >windowslivehelp.com/community/t/35178.aspx</A><br><br>Hotmail has a problem and they seem to refuse to acknowledge it.<br><br>mady<br><small>--<br>Honi soit qui mal y pense</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22396112</guid>
<pubDate>Fri, 15 May 2009 20:31:43 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22396038</link>
<description><![CDATA[Snowy posted : The larger, more organized groups that are involved with the exploitation of home machines for commercial purposes don't parse the data manually. It's done via keyword scripts & sometimes I may see an occasional "gmail" or "mail.yahoo" entry, I can't recall ever seeing "hotmail" used as a keyword.<br>I suppose a smaller operator might believe the few cents they would get for that info justifies the effort but the cost in terms of "lost" machines due to the rightful owner getting a heads up that they have may have a compromised machine because of a compromised hotmail account makes it a losing proposition.<br>But then again, anything is possible because trying to figure out what makes some of these people tick is next to impossible.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22396038</guid>
<pubDate>Fri, 15 May 2009 20:13:54 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22396031</link>
<description><![CDATA[nwrickert posted : <div class="bquote">It defies common sense that user side machines are being compromised for hotmail credentials.</div>We see phishing activity to get student and faculty authentication data, and then the compromised accounts are used for spamming.  It isn't the user machine being compromised in that case, but it also isn't the server being compromised.<br><br>I assume that the same kind of phishing activity goes on with hotmail, yahoo, gmail and similar services.<br><br>Incidentally, the phish mails I have seen for this typically ask for a response by email, so they don't contain any phish url that could be listed with &raquo;<A HREF="/phishtrack">/phishtrack</A><br><small>--<br>AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.10</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22396031</guid>
<pubDate>Fri, 15 May 2009 20:11:53 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22395956</link>
<description><![CDATA[TearAbite posted : I'd disagree that accounts being compromised on the user end defies common sense, but i do agree that Hotmail accounts being hacked is on the increase.  After one of my wife's old hotmail accounts was sending out money requests to all of her contacts via Western Union for her "trip to nigera", i did some searching and found that it is indeed happening to a LOT of other people, beginning around January or so of this year.  <br><br>We use only Mac's, so the chances of one of our machines being compromised is very low - so something is going on here.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22395956</guid>
<pubDate>Fri, 15 May 2009 19:54:02 EDT</pubDate>
</item>

<item>
<title>Re: Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Re-Hotmail-hacked-22395931</link>
<description><![CDATA[Snowy posted : It's extremely irresponsible of hotmail to suggest that the problem is a user side problem. It defies common sense that user side machines are being compromised for hotmail credentials. Gathering hotmail credentials from compromised home machines isn't an activity I've ever seen or expect to ever see & trust me, I've seen a lot! :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Hotmail-hacked-22395931</guid>
<pubDate>Fri, 15 May 2009 19:48:33 EDT</pubDate>
</item>

<item>
<title>Hotmail hacked?</title>
<link>http://www.dslreports.com/forum/Hotmail-hacked-22395741</link>
<description><![CDATA[madylarian posted : I wasn't sure if this should go here or the Security forum, so mods can move it if it's in the wrong place.<br><br>After a spam was sent from my Hotmail account (which I only use for junk mail), I did some searching and found that this has happened to a LOT of people.  The spam is for <i>sell-good.com</i> and typically is sent to everyone in one's contact list.  I found posts about this back in March, but evidently it is still happening and Hotmail is being too damn quiet about it.  Even posts about it in the WindowsLive forums only get canned responses to make sure their computers are not infected.<br><br>I don't care if I lose the Hotmail account as I have others that are equally useful and junk account accounts.  What bothers me is that it appears as if Hotmail only wants to point a finger at the users when they need to look at their own servers!<br><br>Btw, yes, I am sure my computer is clean.  Besides my installed and up-to-date antivirus, antimalware, and antispyware programs, scans by TrendMicro, Hijackthis and Malwarebytes were checked by one of DSLR's own experts.<br><br>mady<br><small>--<br>Honi soit qui mal y pense</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Hotmail-hacked-22395741</guid>
<pubDate>Fri, 15 May 2009 18:56:16 EDT</pubDate>
</item>

</channel>
</rss>

