All the latest UK technology news, reviews and analysis

Hacked Hotmail accounts used weak passwords

by Dave Neal

More from this author

07 Oct 2009

Comments: 2

  • Tweet this
Password screen
The most common password revealed in the Hotmail attack was '123456'

The majority of passwords revealed in the recent Hotmail phishing attack would not have taken much cracking in the first place, according to a researcher at security firm Acunetix.

Bogdan Calin said in a blog post that an analysis of the phishing attack and the hacked accounts revealed that the most common password was '123456'.

The details of some 10,000 Windows Live Hotmail accounts were posted online by an anonymous hacker earlier this week, and Calin suspects that it was rather a crude attack that managed to grab just low-hanging passwords.

"My impression is that these passwords have been gathered using phishing kits. Even more, the phishing kit used most probably was badly designed. I think it just returned an error message after grabbing the credentials. I noticed this because some of the passwords are repeated once or twice (sometimes with different capitalisation)," he wrote.

"What most probably happened is that the users didn't understand what was happening, and they tried to enter the same password again and again, thinking the password was wrong."

Calin found that the most popular passwords were rather similar, and that the majority were made up of alphanumeric combinations, as opposed to the often recommended letter/number/symbol combinations. Sixty-four accounts used '123456', and the second most common was '123456789' with 18 users.

Forty-two per cent of users stuck with lower case alpha passwords containing only characters from 'a' to 'z', and 19 per cent used numeric passwords containing only the numbers '0' to '9'. Just six per cent used mixed passwords containing letters, numbers and other characters.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Web C# ASP.NET Developer (Equity or Mutual Funds) London

Web C# ASP.NET Developer (Equity or Mutual Funds) London...

Senior Exploratory Tester - Selenium, Java, AJAX, WEB

Senior Exploratory Tester - Selenium, Java, AJAX, WEB...

SQL DBA/ Data Architect (T-SQL, SSIS, ETL) - Derivatives

SQL DBA/ Data Architect (T-SQL, SSIS, ETL) - Derivatives...

Test Analyst (Web, QTP, VB.NET, SQL) Wolverhampton

Test Analyst (Web, QTP, Test Director, VB.NET, SQL...

To send to more than one email address, simply separate each address with a comma.