Friday, October 23, 2009

Latest email phishing scam and the pattern of users passwords

A list of 10,000 users was posted online from a phishing scam to pastebin.com website. Initally it was thought that only microsoft's hotmail was compromised but later more details emerged and the results are more shocking there was a lot more than hotmail accounts, the compromised accounts in the second list were from various email providers including Yahoo, Gmail, Comcast and AOL.
One thing is sure, both the leaked lists were not just a small kiddie trick it looks like an organized phishing scam against the major eMail providers. Whatever it was the fault is of the users, they use easy to guess passwords and don't pay attention where they are entering their data and on what websites.

Some of the trends were drawn by accunetix from the leaked email lists is intresting.

The top 20 most common passwords from the list

1. 123456 - 64
2. 123456789 - 18
3. alejandra - 11
4. 111111 - 10
5. alberto - 9
6. tequiero - 9
7. alejandro - 9
8. 12345678 - 9
9. 1234567 - 8
10. estrella - 7
11. iloveyou - 7
12. daniel - 7
13. 000000 - 7
14. roberto - 7
15. 654321 - 6
16. bonita - 6
17. sebastian - 6
18. beatriz - 6
19. mariposa - 5
20. america - 5


Password length distribution
1 chars – 2 – 0%
2 chars – 4 – 0%
3 chars – 4 – 0%
4 chars – 31 – 0%
5 chars – 49 – 1%
6 chars – 1946 – 22%
7 chars – 1254 – 14%
8 chars – 1838 – 21%
9 chars – 1091 – 12%
10 chars – 772 – 9%
11 chars – 527 – 6%
12 chars – 431 – 5%
13 chars – 290 – 3%
14 chars – 219 – 2%
15 chars – 157 – 2%
16 chars – 190 – 2%
17 chars – 56 – 1%
18 chars – 17 – 0%
19 chars – 7 – 0%
20 chars – 14 – 0%


The pattern does tell us that Alexander is one of the most famous password in spanish language.
Read more...

No comments: