[TriLUG] weak email passwords...

Mauricio Tavares via TriLUG trilug at trilug.org
Mon Jul 3 12:03:10 EDT 2017


On Mon, Jul 3, 2017 at 9:39 AM, Chris via TriLUG <trilug at trilug.org> wrote:
> When dealing with an organization, it could also be that the email address and password perform double duty as login credentials.
>
> Chris

      An example of that would be a company or educational institution
which switched to, say, office365: once you have the password you can
now login and access all the files and groups and "teams" this user
has access. While there, why not add a nice little macro into a
spreadsheet file here or a remote shell there? And, while at it, if
you see people online in your chat thingie, send them a message with a
link for good measure. Putting all the eggs in one basket makes life
much easier for the lazy cracker.

>
> On July 3, 2017 9:34:10 AM EDT, Bill Farrow via TriLUG <trilug at trilug.org> wrote:
>>On Mon, Jul 3, 2017 at 8:32 AM, mr-trilug via TriLUG
>><trilug at trilug.org> wrote:
>>> Do weak email account passwords provide a good entry point for
>>hackers
>>> trying to gain access to more important parts of a system?
>>
>>A compromised email account can be used to gain access to other
>>systems by requesting a password reset, which is typically sent via
>>email to compromised email account.
>>
>>
>>Bill
>>--
>>This message was sent to: bick <bick at bickhaus.net>
>>To unsubscribe, send a blank message to trilug-leave at trilug.org from
>>that address.
>>TriLUG mailing list : https://www.trilug.org/mailman/listinfo/trilug
>>Unsubscribe or edit options on the web :
>>https://www.trilug.org/mailman/options/trilug/bick%40bickhaus.net
>>Welcome to TriLUG: http://trilug.org/welcome
>
> --
> Sent from my Android device with K-9 Mail. Please excuse my brevity.
> --
> This message was sent to: raubvogel at gmail.com <raubvogel at gmail.com>
> To unsubscribe, send a blank message to trilug-leave at trilug.org from that address.
> TriLUG mailing list : https://www.trilug.org/mailman/listinfo/trilug
> Unsubscribe or edit options on the web  : https://www.trilug.org/mailman/options/trilug/raubvogel%40gmail.com
> Welcome to TriLUG: http://trilug.org/welcome


More information about the TriLUG mailing list