Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Apr 24, 2024

A Chat with MrChikri via Celebrity’s Hacked Twitter Account

NOTE: The following article was first published on the now-defunct EduTechGuys WordPress site. The text was recovered from the WayBackMachine on the Internet Archive. Most of the embedded images are lost because Archive.org does not preserve images over certain file sizes. I am posting here so I have an accessible copy of it. Any red boxes in the posted images were added by me to protect personal information.
A Chat with MrChikri via Celebrity’s Hacked Twitter Account
by David | Nov 9, 2016 | General Education, Interview, Quick Tip | 0 comments
While following my Twitter feed earlier today, I saw a post from Dave Coulier (yes, as in “Uncle Joey” from “Full/Fuller House”) saying that he had some important news. I responded, not sure I qualified as a “News Reporter.” The account responded, letting me know they had hacked the account and wanted to talk about how they did it and what people can do to protect their accounts.
I struck up a conversation with a user going by the name of “MrChikri.” MrChikri said he was from London.
What follows is the transcript of that conversation (Note: all spellings, grammar, etc are left in tact from the transcript):
davidinark: So, you hacked a celebrity account and I reached out in reply (honestly not realizing it had been hacked). Can we talk about HOW you managed to hack the account, and then, more importantly, how do celebrities (and anyone else) protect themselves from being hacked?
After several moments of waiting, little dots began pulsing on the screen as MrChikri typed out an answer. The response came a full 7 minutes after my initial questions.
MrChikri: hackers that hack celebrities social media accounts are all using the same method, anyone can use this method to hack celebrities even you. all it takes is access to one website called http://leakedsource.com  and money for a subscription.
MrChikri: when big sites like linkedin, myspace etc gets hacked http://leakedsource.com  gets the database of the site and in the database it includes passwords,emails,usernames
MrChikri: i searched daves email on leakedsource and it gave me a list of sites that the email has been registred to
MrChikri: i have a subscription on leakedsource so let me show you a screenshot of how it can look like when getting the password.
davidinark: Ok, what does that look like?
MrChikri: even if you dont have a subscription on leakedsource you can still search emails,usernames but you won’t be able to see the info on it
davidinark: Feel free to block out passwords, etc.
MrChikri then posted the following image (note, all red boxes were added by me, davidinark):
(IMAGE NOT PRESERVED)
MrChikri: here is dave, myspace got hacked 2013 and over 360M passwords were leaked and as you can see daves was one of them
davidinark: Wow!
MrChikri: if you have a subscription this is how it will look like:
(IMAGE NOT PRESERVED)
davidinark: So, this means that Dave hadn’t updated his password since at least 2013!?
MrChikri: yes sir
MrChikri: most celebs use same passwords on all social media
MrChikri: i managed to get into daves instagram account with 500K followers
MrChikri: because he have been using the same passwords for his social media wich is very bad to do
davidinark: Yoy. Yes, that is VERY bad thing to do. I can only suppose that people get relaxed and assume everything is safe. They leave their passwords the same for years and never realize how exposed they have made themselves.
MrChikri: people like kylie jenner, katy perry, drake etc have been hacked using this method.
MrChikri: my tip is just change your password every month and don’t use same passwords on same social medias, also make sure you enable “Login Verification” on twitter and “2 Step verification on your emails” and “2 Factor Authentication” on your instagram
davidinark: I have to ask what keeps you from doing bad things on their accounts? Why are you willing to expose the problem and talk about it rather than cause absolute havoc, as many hackers would normally be apt to do?
davidinark: Your advice is spot on! I hope you are able to communicate that to the celebrities and others who AREN’T updating/changing their info!
MrChikri: well tbh i tweet crazy stuff to it just depends who the person is,
davidinark: Haha, nothing malicious, just crazy, eh?
MrChikri: i mainly hack accounts just to promote my instagram & snapchat, never my twitter cause i just got suspended today thats why im dming you off this one
davidinark: I assumed this was a burner account. 🙂
MrChikri: instagram is very easy to hack though you won’t belive it
MrChikri: lol
MrChikri: you heard about One Direction?
davidinark: Getting hacked? No. What happened there?
MrChikri: instagram should patch this way to hack accs cause this is just (ridiculous)
MrChikri: all you have to do is this
MrChikri: google “instagram report hacked account” and go to that link, https://www.facebook.com/help/instagram/contact/740949042640030 … and this should come up
leakedsource03
MrChikri: so then u just put ur username and etc
MrChikri: 5-10 mins after you will recieve an email saying this
(IMAGE NOT PRESERVED)
MrChikri: so this might seem hard but it is very simple, i putted in @twhiddleston ‘s instagram account to get into it, and then googled “Tom hiddleston holding a paper”
MrChikri: i found this and it matches the instagram email that they want me to do
leakedsource06
MrChikri: then i just photoshopped the picture as you can see it does look legit
MrChikri: i sent that pic to them and after 17 hours i got this email
(IMAGE NOT PRESERVED)
davidinark: Very legit! (In response to the “legit” comment above)
MrChikri: they gave me a link to reset the password and then i got into his account
leakedsource08
MrChikri: this is how dumb instagram is!
davidinark: Yeah, I can see where that wouldn’t be hard to do at all. So, how would someone stop that from happening to themselves?
MrChikri: if you go into your instagram settings and scroll down til you see “Two-Factor Authentication” and enable that, do you know what that is?
davidinark: Yeap! (**See below)
MrChikri: yes that’s what you need to do enable that, but i know a way to bypass that
MrChikri: i can only bypass it on instagram
davidinark: Definitely need that enabled on any accounts that offer it.
davidinark: I appreciate you taking the time to explain how it is done, but even more that you are interested in helping folks PREVENT it in the first place.
MrChikri: there is one more thing i need to say about twitter hacking. On twitter someone hacks you, you’re first changing the password right and then think that the hacker got logged out of the acc cause you changed the pass
davidinark: Right…
MrChikri: but when changing a twitter password you need to goto “Apps connected” and revoke every device from the account
MrChikri: then the hacker gets logged out
MrChikri: now dave got his account back but he only changed his password, i still have access to his twitter…
davidinark: Ah! Yeah, I bet most folks don’t know about that or even think about that!
MrChikri: literally no one that i’ve hacked does that lol
davidinark: Well, I am glad I reached out to Dave’s (er, your) tweet. Thank you for sharing HOW the accounts get hacked and how folks can PREVENT it from happening in the future.
I then asked MrChikri to look up my account information in the system to see if I was in there. I was. Luckily, the information turned out to be stale (old), but MrChikri’s advice is spot-on: Change the info anyway!
**NOTE: Two-Factor Authorization is a security measure in which verification takes place using TWO forms of ID. This usually entails using a cell phone number that receives a text with a special code to be entered for verification. The user gets a text from the site. If everything is on the up-and-up, the user enters that code on the site. If a user gets a request to enter the code but they never asked for the code, someone is trying to hack the account.

Jan 22, 2019

#Ransomware Attack at School Triggers Best Practice Reminders

 
Recently, there was a ransomware incident at a nearby school district. The event occurred through a Remote Desktop Protocol Session (RDP) running on the Technology Coordinator's desktop. His machine had a publicly accessible RDP IP address so he could work from home, etc. Unfortunately, his computer was compromised and subsequently used to attack their servers.

If you are using RDP to get access to your network from outside, I recommend the following:
  1. Kill all RDP sessions accessible from outside your internal network. This may require editing your firewall settings to remove the public IP address(es) to your RDP computers.
  2. Change your password on any accounts used for accessing public RDP. The current en vogue system is to use passphrases rather than passwords.
  3. If you must have remote access, set up a VPN to handle that instead of RDP.Several companies offer secure VPN access.
  4. Do NOT put your own login account into the Domain Admins group.
  5. For internal RDP sessions, do *NOT* save the logon credentials. I know it is a pain, but better safe than sorry. :-)

Oct 20, 2009

Time keeps on tickin, tickin, tickin...

Wow, I cannot believe how quickly time slips away from me!  A lot of that is because of how busy these past few days have been.  Monday, we had yet another break in at work.  It's gotten to the point that I bought a security system to install at work.  We're putting in up to 12 cameras with a DVR.  The cameras are all indoor/outdoor and infrared, so we should be able to at least get anyone coming in on video.


Today (Tuesday), I got the first camera up and running, I had to, er, um, test it, so I did a few wild gestures in order to trigger the motion detector.  Of course, I could have just walked in, but what's the fun in that?  Well, after we figured out how to replay the video, my co-workers said we should put it on youtube, or America's funniest videos... Great.



Jeff (from Hope schools) and I helped during a workshop today in which administrators received iPaq handheld Windows machines.  Things went pretty well, except that the software they are using (CWT from Teachscape) has a SERIOUS design flaw!  The program does not actually fully stop running when you click the "X" to close out of the program!  What the heck?  Tech support told us that the users MUST use the Actions > Exit, then Actions > Exit again to fully close out of the program.  This seems to only affect the Windows mobile version of CWT.  The "fix" is to go into the "running programs" setting and end all programs, then the software will launch as it is supposed to.  OY!



After I left there, I ran over to the early childhood classroom because they were having trouble with their Smart Board.  Turns out that a USB extender that was under a carpet behind some equipment became disconnected.  Nice, easy fix!  I love those!



From there, I ran over to Spring Hill though I had forgotten what I was going to help with.  I was quickly brought up to speed: two routers, two networks, want to be on one domain.  That is a little beyond my expertise, so I called Jeff for some help and insight.  It turns out, this is a bit more complicated that we anticipated because of the way the state has things set up at the two different locations.  My next step is to call in the folks at DIS and get them to help us out.  They set it up this way, they can help us get it working correctly, right!?




Shan was asked to lead a bunch of girls (who have NEVER twirled batons before!) in a program for Homecoming.  She has been staying after school this week for Friday's big event.  She and Michelle worked out a routine, and tonight (at home) she showed me the routine set to music.  It is WAY COOL! The girls are going to go NUTS when they finally put the routine to music.  They all look like they are having fun!



Need a reason to have Twitter or Facebook for your school district?  How about this: create a group, then have faculty, staff, students, parents, etc join the group.  Use the group to post announcements of upcoming events, network status (campus down, issues, upgrades, etc), or other district news.  Keep the posts short and sweet with links (if needed) to more information.  Include pictures as applicable.

An extension of this would be a tech-specific twitter/facebook group for your district.  In this group, include key campus personnel, all the techs in your district, perhaps your service area technology coordinator.

This idea is not mine, but is rather the brain-child of Jeff at Hope schools.  He comes up with some seriously great ideas!  I just try to help implement them. :-)