gmail hack

Started by angler, December 03, 2009, 06:39:24 AM

Previous topic - Next topic

angler

My GF's gmail and FB accounts got hacked this morning.  I'm calling it a hack because it doesn't seem like a virus, but could be.  It has been sending fraud emails asking for $$ and IM'ing people through both gmail and FB.  It has been changing her passwords to both accounts every time she changes them, so she keeps getting locked out of both accounts. 

Any tips?  I'm on FB, but not on gmail so should I be worried?
996 forks, BoomTubes, frame sliders, CRG bar-end mirrors, vizitech integrated tail light, rizoma front turn signals, rizoma grips, cycle cat multistrada clip ons, pantah belt covers - more to come

The whole aim of practical politics is to keep the populace alarmed (and hence clamorous to be led to safety) by menacing it with an endless series of hobgoblins, all of them imaginary. H. L. Mencken

Monster Dave

As a risk assessment specialist, I have to ask:

1) Are either of her user name/passwords the same for both Gmail and FB?
2) Did she respond to a message in either that warned her that her account would be locked out or deleted if she didn't submit the information from question #1?

angler

Quote from: Monster Dave on December 03, 2009, 06:44:22 AM
As a risk assessment specialist, I have to ask:

1) Are either of her user name/passwords the same for both Gmail and FB?
2) Did she respond to a message in either that warned her that her account would be locked out or deleted if she didn't submit the information from question #1?

Unfortunately they were the same (not smart).  They are now different and her FB account has been shut down.

I'll ask about #2.  If the answer is yes, she is never touching my computer again!  

I've heard that this some sort of worm.
996 forks, BoomTubes, frame sliders, CRG bar-end mirrors, vizitech integrated tail light, rizoma front turn signals, rizoma grips, cycle cat multistrada clip ons, pantah belt covers - more to come

The whole aim of practical politics is to keep the populace alarmed (and hence clamorous to be led to safety) by menacing it with an endless series of hobgoblins, all of them imaginary. H. L. Mencken

Monster Dave

Quote from: angler on December 03, 2009, 06:50:50 AM
Unfortunately they were the same (not smart).  They are now different and her FB account has been shut down.

I'll ask about #2.  If the answer is yes, she is never touching my computer again!  

I've heard that this some sort of worm.

That's an unfortunate error made by a lot of people out of a desire to standardize access to various secure logins - but from a risk assessment perspective, it's an awful thing to do. It's like having one key that works for your car, motorcycle, motorcycle disk lock, house, etc....

I've really had to work hard to have the people in my office check with me when they get what looks like a credible email asking for their login information. Most of the time, when they unfortunately do choose to respond to such emails, it's due to a threat of account termination or some sort of threat like "if you don't respond withing X amount of time...."

It makes me want to smack someone when they respond because I don't know how many time I've said that I will NEVER ask for user/logon information via email....but they do it anyway!!!!  [bang]



derby

Quote from: angler on December 03, 2009, 06:50:50 AM

I've heard that this some sort of worm.


it's not really a worm. her credentials were most likely phished and there's an automated process (bot) handling the rest of the business (spam/passwd changes).
-- derby

'07 Suz GSX-R750

Retired rides: '05 Duc Monster S4R, '99 Yam YZF-R1, '98 Hon CBR600F3, '97 Suz GSX-R750, '96 Hon CBR600F3, '94 Hon CBR600F2, '91 Hon Hawk GT, '91 Yam YSR-50, '87 Yam YSR-50

click here for info about my avatar

angler

Quote from: derby on December 03, 2009, 07:38:50 AM
it's not really a worm. her credentials were most likely phished and there's an automated process (bot) handling the rest of the business (spam/passwd changes).

So far the best tip I've heard is to delete everything in the gmail account and walk away from it.  Sounds a bit drastic - any other tips?
996 forks, BoomTubes, frame sliders, CRG bar-end mirrors, vizitech integrated tail light, rizoma front turn signals, rizoma grips, cycle cat multistrada clip ons, pantah belt covers - more to come

The whole aim of practical politics is to keep the populace alarmed (and hence clamorous to be led to safety) by menacing it with an endless series of hobgoblins, all of them imaginary. H. L. Mencken

Monster Dave

I'd say that's too drastic. Just change her credentials and make them "strong" - 7-12 letters include caps, symbol and a number.

Mad Duc

#7
Go to a different PC and change the passwords. Then go to the "secret questions" and change questions (if you can) and the answers to something that isn't right or logical - Q: "what street did you grow up on?" A: "11,111,111"

If it is a local password logger this will make is so that it can't catch your password. If is a remote one then it can't answer the questions properly to reset your password.

For google here's the page to change those settings:
https://www.google.com/accounts/UpdateAccountRecoveryOptions?service=mail

I can't get to FB at work or else I would post up that link too.
PA's official Ducati Owner's Club: PennDesmo.org

il d00d

You may also try contacting google to let them know the account has been hacked - they may be able to suspend the account until your girlfriend can verify ownership, prevent her from ending up on black lists etc.  Hopefully they can erase all used passwords and establish a new set of credentials.

https://www.google.com/support/accounts/bin/request.py?ara=1&hl=en&contact_type=ara&ctx=ara

ducatiz

Quote from: il d00d on December 03, 2009, 09:01:36 AM
You may also try contacting google to let them know the account has been hacked - they may be able to suspend the account until your girlfriend can verify ownership, prevent her from ending up on black lists etc.  Hopefully they can erase all used passwords and establish a new set of credentials.

https://www.google.com/support/accounts/bin/request.py?ara=1&hl=en&contact_type=ara&ctx=ara

right, and get a reply 2 months from now?
Check out my oil filter forensics thread!                     Offended? Click here
"Yelling out of cars, turning your speakers out the window to blast your music onto the street, setting off M-80 firecrackers, firing automatic weapons into the airâ€"these are all well and good. But none of them create a merry atmosphere of insouciance and bonhomie quite like a revving motorcycle.

il d00d

Quote from: ducatiz on December 03, 2009, 09:17:18 AM
right, and get a reply 2 months from now?

Exactly.  I mention this because I want this to be process as long and painful as possible.  I forgot to mention, also change her password to her credit card number, then post that update on facebook.

Wow.  Not feeling the love from the board today.

angler

#11
Thanks everybody.  I knew I would get some good stuff here.  All my credentials are real tough, but I'll pass these along to her just as soon as I reply to an email about 10,000,00 US$ waiting in a bank in Nigeria for me.
996 forks, BoomTubes, frame sliders, CRG bar-end mirrors, vizitech integrated tail light, rizoma front turn signals, rizoma grips, cycle cat multistrada clip ons, pantah belt covers - more to come

The whole aim of practical politics is to keep the populace alarmed (and hence clamorous to be led to safety) by menacing it with an endless series of hobgoblins, all of them imaginary. H. L. Mencken

cyrus buelton

Does she have an ex-boyfriend that would want to be reading her personal messages?


just sayin'
No Longer the most hated DMF Member.

By joining others Hate Clubs, it boosts my self-esteem.

1999 M750 (joint ownership)
2004 S4r (mineeee)
2008 KLR650 (wifey's bike, but I steal it)

angler

Quote from: Mad Duc on December 03, 2009, 08:10:24 AM
Go to a different PC and change the passwords. Then go to the "secret questions" and change questions (if you can) and the answers to something that isn't right or logical - Q: "what street did you grow up on?" A: "11,111,111"

If it is a local password logger this will make is so that it can't catch your password. If is a remote one then it can't answer the questions properly to reset your password.

For google here's the page to change those settings:
https://www.google.com/accounts/UpdateAccountRecoveryOptions?service=mail

I can't get to FB at work or else I would post up that link too.

Thanks a bunch from the GF.  The link turned out to be super helpful.  Hopefully she is all squared away.
996 forks, BoomTubes, frame sliders, CRG bar-end mirrors, vizitech integrated tail light, rizoma front turn signals, rizoma grips, cycle cat multistrada clip ons, pantah belt covers - more to come

The whole aim of practical politics is to keep the populace alarmed (and hence clamorous to be led to safety) by menacing it with an endless series of hobgoblins, all of them imaginary. H. L. Mencken

angler

Quote from: ducatiz on December 03, 2009, 09:17:18 AM
right, and get a reply 2 months from now?

She actually contacted them first and got an almost instant response.
996 forks, BoomTubes, frame sliders, CRG bar-end mirrors, vizitech integrated tail light, rizoma front turn signals, rizoma grips, cycle cat multistrada clip ons, pantah belt covers - more to come

The whole aim of practical politics is to keep the populace alarmed (and hence clamorous to be led to safety) by menacing it with an endless series of hobgoblins, all of them imaginary. H. L. Mencken