Compromised Mailaccounts FAQ

Q: Where did you get the lists from?
A: We got the lists right of the web, using a browser and a search-engine. We didn't ask anybody to give us data nor did anyone give us data. We opened the lists in a browser and put them in a database. Some of the lists are publicly on the web since september 2009, some are from october 2009. All were public, indexed and partially cached by major search-engines. At least one of the lists with >25.000 lines is currently (10/12/09) available via http://rapidshare.com as well.

Q: Did you buy the lists?
A: No. In fact, account-lists like those we downloaded from public webpages are for sale; 10.000 accounts will cost you an average of 90 US$. We did not and will never support those type of criminal business.

Q: Will you save my address?
A: The data you enter in our mailaccount-page will NOT be saved. Our server will log your IP, browserstring and referrer like all webservers do, but we will NOT log or save the data you enter in our check. (There is no sense in doing that!)

Q: Will you give away those lists?
A: No. If you are really keen on getting them, your favourite searchengine will help you find them yourself.

Q: How many lists are there?
A: Currently we know of two big lists with together around 35.000 lines and a bunch of smaller lists. We are sure that there are far more lists floating around, most of them beeing NOT publicly available.

Q: Is my mailprovider affected, too?
A: We don't know. There are plenty of hotmail, yahoo and gmail-adresses, but there are also live.com, googlemail.com, aol.com and many other mailproviders to be found in the lists.

Q: Is there a way to see a listed account?
A: Go and check the account “serversniff” - we added this as testcase to our lists.

Q: Why are you doing this?
A: To show you, that it's time to change your passwords. The fact that you were curious if your account is affected should make you think. Go and change your important passwords NOW, if didn't already do.

If you have further questions, drop me a mail: tom@serversniff.net

 
Back to top
mailaccount-faq.txt · Last modified: 2009/10/12 16:42 by Thomas Springer
 
 

Imprint | Terms of use
This site uses Thumbshots previews
sniffing since 2004