site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
1152
Share Topic
Posting?
Post a:
Post a:
Links: ·Status Page ·FAQ ·SBC Techs ·Anti-virus and spyware
AuthorAll Replies


privatepilot
Premium
join:2004-05-25
Evansville, IN

1 edit

Yahoo account was hacked this morning

Just a heads up! My primary yahoo account was hacked this morning and all my contacts were 'removed'. Several phone calls informed me I was asking for $2500 to be sent to London etc etc

I've spent the entire day rebuilding the contact list, checking banks, credit card etc.. not a fun time!

I would advise all to change your yahoo account passwords to a long and complicated set of characters. Some one worked hard to break my code.. pp

P.S. the originating IP seems to be 66.94.236.23 that has been the origin of lots of 'bad' stuff


justbits
More fiber than ATT can handle
Premium
join:2003-01-08
Chicago, IL
Reviews:
·AT&T Midwest
·AT&T Yahoo

bash-3.2$ host 66.94.236.23
23.236.94.66.in-addr.arpa domain name pointer nm18-vm0.access.bullet.mail.mud.yahoo.com.

That IP is a valid Yahoo Mail Server. It's likely that they automated some IMAP or Web based email spamming program to originate the email through your Yahoo account.

You'll need to look closer at the email headers to see which IP connected to webmail or SMTP submission. Have your friends forward the email if they still have it. Heck, Yahoo likely still has the email records for the abuse too.

Example:
Received: from [99.142.56.1] by web81104.mail.mud.yahoo.com via HTTP; Tue, 10 Jan 2012 06:29:08 PST
X-Mailer: YahooMailClassic/15.0.4 YahooMailWebService/0.8.115.331698

That would direct you to the true IP address of the 'attacker'.



StillLearn
Premium
join:2002-03-21
Streamwood, IL

reply to privatepilot
Did your password get changed? This kind of hacking would often be via getting tech support to reset your password. If your old password worked, then that would not be the case.

I tend to think that the best strategy is to not use your "main" email address for anything but communicating with ATT. Too late now, but others might do that.


jlibuszowski
Premium
join:2005-10-25
Hoffman Estates, IL
Reviews:
·AT&T (Business S..
·Verizon Wireless..

said by StillLearn:

Did your password get changed? This kind of hacking would often be via getting tech support to reset your password. If your old password worked, then that would not be the case.

I tend to think that the best strategy is to not use your "main" email address for anything but communicating with ATT. Too late now, but others might do that.

Your account probably got fished, i.e. you clicked on an email that purported to be from Yahoo when infact it was some hacker or asshat... That said, Yahoo email is the worst in terms of security they just suck! I would get a gmail account and enable 2 factor authentication and be done with it, if you have that option.

Typically Yahoo email/ ATT is where things go to die. Just saying. Heck Yahoo even allowed me to register a email that was previously used on yahoo, and I kept getting this woman's Obama propaganda emails.. it was quite funny


privatepilot
Premium
join:2004-05-25
Evansville, IN

Here is part of the header I captured:
Received: from [66.94.237.196] by nm8.access.bullet.mail.mud.yahoo.com with NNFMP; 17 Jan
2012 15:28:30 -0000
Received: from [66.94.237.106] by tm7.access.bullet.mail.mud.yahoo.com with NNFMP; 17 Jan
2012 15:28:30 -0000
Received: from [127.0.0.1] by omp1011.access.mail.mud.yahoo.com with NNFMP; 17 Jan 2012
15:28:30 -0000
X-
Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 329800.72447.bm@omp1011.access.mail.mud.yahoo.com
Received: (qmail 1164 invoked by uid 60001); 17 Jan 2012 15:28:30 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1326814110;
bh=a5fJ8JQQEM7ojl/18XkKbt1zWZMYhifyXnnlp3KITg4=;
h=X-YMail-OSG:Received:X-Mailer:Message-ID:Date:From:Subject:To:MIME-Version:Content-Type;

There is more but this might give someone a clue??
pp



privatepilot
Premium
join:2004-05-25
Evansville, IN

reply to privatepilot
I did NOT reply to any request to 'reset' my password etc. (I've been around for too many years to fall for that one)

The 'hacker' sucked out all my yahoo contacts, deleted them and then changed my email ID slightly (ch'd an 'o' to '0'). All my other yahoo/att ID were deleted except the original which allowed me back in to undo the dastardly deed. (one dumb move on their part)

Of course, I then changed my pwd but the horse had left the barn..

I agree that one should only use the main yahoo log on ID for just its intended purpose. And have a very unique pwd for that.
pp


jlibuszowski
Premium
join:2005-10-25
Hoffman Estates, IL
Reviews:
·AT&T (Business S..
·Verizon Wireless..

Sorry to hear that. Call customer service up and ask for it to be reset. Then as I suggested try and make a move to google or similar service, that has 2 factor authentication or at least has a little better security to prevent cr@p like this from happening.

I had a similar issue many years ago, with some somewhat revealing pictures a woman decided to apparently send through email of us together... Well surprise surprise some f*cktard hacked into an account of mine. The response from some foreign customer service for ATT was well less than responsive. They eventually got it straightened out... But it wasn't until after I told the customer service dude "Look I don't care how long this takes, just get it fixed!"

Anyway sorry your horses also left the barn... And just try to go for a slightly more secure email provider.


Friday, 01-Jun 19:01:39 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics