HomeSecurityInternet: How safe are we?

Internet: How safe are we?

Image 1: When an admin is… forgetful, others "pay" for it!
Image 1: When an admin is… forgetful, others "pay" for it!

We must admit and feel (some of us) lucky to have experienced the birth of a revolution that, in the writer's opinion, has been happening since the invention of the wheel: The revolution of the internet and the electronic age.

The internet, in addition to other advantages (philosophical and otherwise), tends to free us from many tedious, laborious, time-consuming and irritating procedures, such as: Standing in line at a cashier to pay our bills, monitoring our bank account, purchasing almost all goods from online stores (we can buy everything from books to… bookstores!), going back and forth to the post office for our mail and many more that would easily require 10Gb of space, not to mention anything else…!

We can do all these amazing things calmly and beautifully from the armchair of our home. Isn't it much better? Of course! Isn't it much better than running through the streets in the cold or heat, in the hustle and bustle? Let alone outside, you also have to deal with the prying eyes of every gossip. What time did you leave, what time did you come in, where did you go, etc. Besides, you never know how many eyes are watching you behind some "grilles"! The problem, however, is that these "grilles" can also be... electronic!

In this article, we will put ourselves in the shoes of the person behind the grill. But not in a physical form, but in a virtual one: We will see how easy it is to track someone (even if they are unknown) and collect almost all of their personal information with minimal effort. All this, without using any illegal software or any weakness in any system and without spending anything more than the electricity consumed by our computer. Our only guide: Google.

In an era when the security of personal data is beginning to raise awareness even among public bodies(!!), we will present how easily someone can gain access to a person's extremely personal information, such as their profession, their photo, their name, their age, their family details, their preferences (hidden and not!), their credit cards, their bank accounts, their financial accounts on various internet sites (see PayPal), etc. Did you think we'd gone far enough? Hmm... you haven't read anything yet!

We will also show how easily we can “steal” the “identity” of our victim and appear on the internet (at least) as if we were him or her! Does it remind you of something from… agent 007? We assure you that what we present is absolutely real, it can happen to any of us and we will prove it to you. Of course, at the end we will also give you all the necessary “help” and instructions so that you do not fall or it will be very difficult for you to fall victim to such an unpleasant situation.

We will present the story to you exactly as it happened, without any embellishments or additives. This way you will suspect how someone as curious as us but not at all honest (unlike us) can "work".

So let's get started. Where else: From Google! So, one afternoon, we felt like "searching". To start, we let our dear Google search for directories that contain the classifieds.cgi file. That is:

intitle: "Index of" classifieds.cgi

After we "got" a fairly large list of sites, we started going into each one, hoping to find something interesting. After a little searching, we found a directory with many... sub-directories accessible from the Internet. This is not necessarily a bad thing, as long as someone hasn't forgotten important information there! Once again, we were not disappointed. After all, there are few times when we have searched in directories that "accidentally" allowed the so-called "directory listing" and we didn't find anything important or interesting. Some forgetful administrator (to say nothing more serious - although we should!) had forgotten in a dark (confessed) corner of the disk a file with the codes, passwords, emails and other information of the users of a site (image 1).

Hmm… so what do we have? A list of passwords of some users along with their emails. Ok, with the password and the password we can enter the site even as an admin since the administrator made sure that we didn't miss any information! But that's not enough for us. We also want to test our theory. You will say (and rightly so) "What is your theory?". Our theory (even if it is a secret… don't leak it, okay?) is that a very large percentage of users have the same password for all their activities on the internet. This happens because most people are bored or confused (or both anyway) to maintain and remember many passwords. Ok, this is somewhat logical. What is not logical, however, is to use the same password everywhere, e.g. the password of their main email is the same as the one they registered for in a forum. Based on this theory, we have found that approximately 30% of a site's users fall into this trap.

We will now try the following: We will search for all users with yahoo email and we will try to log into their account one by one, just to see who we will succeed with. Quite by chance, the 3rduser in order of appearance in Figure 1, presented this prototype “vulnerability” (Figure 2)! Does this tell you something? – maybe something in… 33% ;-). As we will see below, this user is not so much… him as she, a fact that will not concern us at all since we are not racists when it comes to gender ;-).

Image 2: Our friend Ms. Lynn and her… correspondence!
Image 2: Our friend Ms. Lynn and her… correspondence!

This is Ms. Lynn's correspondence (okay, don't shout, we only mentioned her first name!!). From what we see in MyFolders, Ms. Lynn has everything neat and... tidy: Her personal messages in one folder, her work messages in another, the forums she is registered in another, etc. etc. It is also worth mentioning the number of emails she maintains on Yahoo: it is no less than... 13969! A significant number? Maybe! It is now a matter of time before we find all her data. See how easy it is, just look for a few basic elements:

Key element #1: We are looking for emails welcoming Lynn as a new member to a forum. These emails usually contain username and password information. One such email is the following:

Image 3: Code and Password for registering on a forum!
Image 3: Code and Password for registering on a forum!

By logging into the forum with her password, we can find even more information about her. We can also reply to other members as if we were Ms. Lynn (see impersonation). In short, we can impersonate Ms. Lynn, make a love confession to one of her friends, reject someone else, and generally make a mess of her life.

Also within the forum we found a very interesting group of information entitled “View Profile”. This is Ms. Lynn’s personal information along with her photo! In the same place is her biography along with phone numbers, addresses and names of friends and relatives (image 4).

Image 4: The personal details of the… "victim"!
Image 4: The personal details of the… "victim"!

Based on the type of forum and this data, we can deduce basic information about Ms. Lynn's preferences and, having her phone number, we can "inform[1]" product promotion companies to market products to her (based on her preferences) with a high probability that she will buy them! We can do the same for her… relatives ;-). Since we got to know the whole family, why not take advantage of it?

Having talked about spam and spammers, let's not forget to mention that the spammer's joy is to "dive" into a sea of ​​real emails. Once again, with profit as our goal, we will not disappoint him by giving him a small list of about 100ths of real emails that we found in the account of the popular (but true) Ms. Lynn (image 4b).

Image 4b: Our "gift" to spammers everywhere... with no compensation!
Image 4b: Our "gift" to spammers everywhere... with no compensation!

In another email we found something equally interesting. Information, usernames and passwords for some domains. Hmm… does Ms. Lynn maintain some sites on the Internet? Yes! In fact, we even accessed her Domain manager, where she has all the URLs she uses listed (image 5).

 Figure 5: Domain names along with DNS Servers!
Figure 5: Domain names along with DNS Servers!

We can easily change the domain manager's password so that she can't log in herself and change the DNS servers by redirecting all the URLs to another address, doing a first-class defacement, or sending her pages to someone else's URL, incriminating them! Bad, huh?

But,… oops! Here there is something more serious: a “My Wallet” option (which for those who didn’t understand means “My wallet”). Entering there we have Ms. Lynn’s credit card details. Okay, it’s not the whole card number but all the other details (region, phone, city, etc.) and the information is not at all negligible (image 6). Take note of the image url. It is a secure connection (https). However, no matter how secure a connection is, there is always a door near or far that bypasses it (“good” time).

Image 6: And Visa card details!
Image 6: And Visa card details!

And now we come to the worst part of the search. Yahoo-mail has a very useful button called “Search”. By clicking on it, we can search for a series of characters (e.g. some words) that appear in one or more emails. We can search for any word we want. We chose completely randomly… the word “PayPal”. For those who don’t… remember(!!) PayPal is an internet service that you can connect to your bank account or credit card and with which you can make purchases by giving only the PayPal code and not your card number itself. Let’s say that we found many PayPal Account emails, but nowhere did we find Ms. Lynn’s PayPal password. Hmm… no need! What we can do is go to PayPal, give Lynn’s email and tell them that… we forgot the password (image 7)!!

Figure 7: Tricking PayPal…
Figure 7: Tricking PayPal…

PayPal will immediately send Lynn's email a new password, assuming that only the real Lynn has access to her email. That's it! We can now make purchases with Lynn's credit or debit card via Paypal.

We can do many more things but let's stop here. We've "played" with Ms. Lynn enough. Let's try any other yahoo mail we found on our list... Do you think we'll be just as lucky (image 8)?

Image 8: Hello Craig…!
Image 8: Hello Craig…!

Hello Mr. Craig! We are ready to know your secrets! History repeats itself.

Conclusions and ways of protection

We have presented a very simple way that someone can violate the privacy (and financial life as well) of another person without the other person knowing anything. We have violated a bunch of pages and secure connections just because some stupid admin decided to leave their user details in a directory accessible from the web. You will ask yourself, and rightly so: “Oh well! My entire private life is in the hands of a stupid admin?” Hmm… the answer is “Unfortunately yes, if you do not follow some basic security rules”. If you have the same password on your neighborhood forum as the one you have to log in to your bank, no one will blame you if you suddenly see a €2000 bill for the trip you just booked to East Timor!

So, base yourself on a few small but golden rules to avoid unpleasant surprises:

  1. Don't be "ashamed" to use many passwords! If you don't remember them, download a Password Manager (there are many available and they are free). For example, you can try KeePass (https://keepass.info/), which is free, uses strong encryption (AES, Twofish) and can work on Linux, Windows and Android.
  2. Be sure to have another email for Public sites and another email with your personal accounts, PayPal accounts, etc.
  3. Choose passwords longer than 10 characters (and shorter than 100) that contain lowercase, uppercase, numbers, and special characters. Special characters are the ones that in old comics they used to put instead of "binelliks", when the hero was irritated and started "downloading"... various things. For example, "@!!~~–//_\\".
  4. Always delete emails that mention codes and passwords. Be careful to delete them from the… deleted ones too!

Finally, don't trust anyone and never forget the general rule of IT security:

The chain is only as strong as its weakest link

The current article is a synthesis of three similar articles that I had written myself in the following media:

  • Total XakeR #22 (Greek magazine for Hacking {DOL & 4π publications} – no longer in circulation).
  • Hackin9 12/11: English version of an online magazine about Hacking – https://tinyurl.com/kxkxsks).
  • P0wnbox.com: Greek forum for security and ethical hacking (https://tinyurl.com/n4ntqet).
  • Unfortunately, it seems that it was copied and published (without citing the source) by other forums (and somewhere else, in case it catches your eye)!

——

[1]              We mean… sell our information!

 

We warmly thank SecTeam member @Thiseas.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS