ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Emerging tech Toolkit

After Hotmail "glitch" UK Excite accounts cracked

Jane Wakefield ZDNet.co.uk

Published: 02 Sep 1999 16:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Excite.co.uk and Ireland.com have fallen victim to an email hack it emerged Thursday, with tens of accounts accessed in the last 24 hours.

Following the Hotmail debacle at the start of the week, one non-techie hack has gained access to the accounts of around fifteen Excite.co.uk and Ireland.com subscribers -- including the unlucky John from London -- in less than an hour.

Stephen Finnegan, managing editor of Web Ireland took a total of 18 minutes to break into an Ireland.com account. Researching for a radio programme on the recent Hotmail intrusions, Finnegan hacked accounts using the simple question and answer mechanisms many sites use if passwords are forgotten.

The password prompt on the site asks a series of questions such as date of birth. Finnegan was able to repeatedly guess the year of birth for an account. Arriving at the correct year revealed the password to get into accounts.

"I did it around five times," he said. "The first time it took around 18 minutes but after that passwords were being revealed every two minutes or so."

Finnegan, a self-confessed non-techie turned his attentions to Excite.co.uk.

"I looked at around ten email boxes in less than 20 minutes," he said. Finnegan claims he did not read any of the email. "I wasn't interested in that. I just wanted to demonstrate how easy it is just with trial and error and the law of averages to get into people's email accounts."

Ireland.com staff were informed immediately and have taken steps to remove the flaw. Excite.co.uk were unable to comment at this early stage.

Worried your mail account may have been affected?

Tell the Mailroom

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
59 out of 126 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Discussions

vorne7789 vorne7789

End of the world?

Friday 8 August 2008, 7:13 PM

1 comment
Andrew Meredith Andrew Meredith

The wrong answer

Friday 8 August 2008, 5:24 PM

2 comments

Featured Talkback

While full medical records may be of (dubious) value at rear/base medical facilities, these could be provided much simpler by either physical disk or electronic transfer to an "in theatre" database for individuals posted in. That £80m (and it's associated running costs) could have been far better employed in resuscitating a disbanded infantry battalion or providing a big boost in equipment quality and quantity.

By: 1000215420

Read full story:
Photos: MoD unveils £80m IT health programme