Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / How they did it Inside the Russian hack of Yahoo

How they did it Inside the Russian hack of Yahoo

Latest Govt. Jobs 16:28:00 News Edit
One mistaken click. That's all it took for hackers aligned with the Russian state security service to gain access to Yahoo's network and potentially the email messages and private information of as many as 500 million people.
The U.S. Federal Bureau of Investigation has been investigating the intrusion for two years, but it was only in late 2016 that the full scale of the hack became apparent. On Wednesday, the FBI indicted four people for the attack, two of whom are Russian spies.
Here's how the FBI says they did it:
The hack began with a spear-phishing email sent in early 2014 to a Yahoo company employee. It's unclear how many employees were targeted and how many emails were sent, but it only takes one person to click on a link, and it happened.
Once Aleksey Belan, a Latvian hacker hired by the Russian agents, started poking around the network, he looked for two prizes: Yahoo's user database and the Account Management Tool, which is used to edit the database. He soon found them.
So he wouldn't lose access, he installed a backdoor on a Yahoo server that would allow him access, and in December he stole a backup copy of Yahoo's user database and transferred it to his own computer.
The database contained names, phone numbers, password challenge questions and answers and, crucially, password recovery emails and a cryptographic value unique to each account.
It's those last two items that enabled Belan and fellow commercial hacker Karim Baratov to target and access the accounts of certain users requested by the Russian agents, Dmitry Dokuchaev and Igor Sushchin.
170315 fbi 2Martyn Williams
A U.S. District Court endictment for four people accused of hacking Yahoo is seen against FBI wanted posters.
The account management tool didn't allow for simple text searches of user names, so instead the hackers turned to recovery email addresses. Sometimes they were able to identify targets based on their recovery email address, and sometimes the email domain tipped them off that the account holder worked at a company or organization of interest.
Once the accounts had been identified, the hackers were able to use stolen cryptographic values called "nonces" to generate access cookies through a script that had been installed on a Yahoo server. Those cookies, which were generated many times throughout 2015 and 2016, gave the hackers free access to a user email account without the need for a password.
Throughout the process, Belan and his colleague were clinical in their approach. Of the roughly 500 million accounts they potentially had access to, they only generated cookies for about 6,500 accounts.
The hacked users included an assistant to the deputy chairman of Russia, an officer in Russia's Ministry of Internal Affairs and a trainer working in Russia's Ministry of Sports. Others belonged to Russian journalists, officials of states bordering Russia, U.S. government workers, an employee of a Swiss Bitcoin wallet company and a U.S. airline worker.
So clinical was the attack that when Yahoo first approached the FBI in 2014, it went with worries that 26 accounts had been targeted by hackers. It wasn't until late August 2016 that the full scale of the breach began to become apparent and the FBI investigation significantly stepped up.
In December 2016, Yahoo went public with details of the breach and advised hundreds of millions of users to change their passwords.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Alcatel 1x with Android Oreo (Go ed...

Huawei P20, P20 Pro, P20 Lite price

Xiaomi Redmi 5 with 18:9 display
How they did it Inside the Russian hack of Yahoo How they did it Inside the Russian hack of Yahoo Reviewed by Latest Govt. Jobs on 16:28:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows 10 Creators Update is here, now—yes,  now —but not (officially) on the PC. The ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Bank wallets growing faster than e-wallets
    In the  bank  versus  e-wallets  sweepstakes,  lenders  have now gained lost ground. As of ...
  • Facebook co-founder learned programming language in 2 days www.goandroidapps.in
    Facebook co-founder learned programming language in 2 days www.goandroidapps.in
    Facebook co-founder learned programming language in 2 days:  Learning an entire programming ...

Random Posts

  • Microsoft's surface book and floor Studio will deliver in more markets
    Microsoft's surface book and floor Studio will deliver in more markets
    30.03.2017 - 0 Comments
    Microsoft has been cautious about making its Surface product line available worldwide. It tests devices…
  • Latest Xiaomi Mi Mix 2 to feature fingerprint scanner inside display
    Latest Xiaomi Mi Mix 2 to feature fingerprint scanner inside display
    04.03.2017 - 0 Comments
    Xiaomi Mi Mix 2 smartphone could feature the fingerprint scanner inside the display. Xiaomi’s upcoming Mi…
  • Battle of flagship phones: Google Pixel vs Moto Z vs Honor 8
    Battle of flagship phones: Google Pixel vs Moto Z vs Honor 8
    06.11.2016 - 0 Comments
    If you're looking for an Android smartphone with a great camera, you're spoiled for…
  • No process losses because of chatbots, AI: Banks
    No process losses because of chatbots, AI: Banks
    06.04.2017 - 0 Comments
    The financial sector in India is driving investments into chatbots and artificial…
  • Garmin Vivoactive HR Review: 100% Legit – Love This Thing!
    Garmin Vivoactive HR Review: 100% Legit – Love This Thing!
    11.02.2017 - 0 Comments
    The Garmin Vivoactive HR is potentially the only fitness tracker you’ll ever need to…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Steam Now Supports PS4's DualShock 4 Controller
    HIGHLIGHTS ...
  • This $15 stand turns your Apple Watch into a mini Macintosh
    For all those  ...
  • MobiKwik - Update E-KYC & Get Rs. 100 Supercash
    MobiKwik - Update E-KYC & Get Rs. 100 Supercash
    Mobikwik - Update ...
  • Fitbit Flex 2017 review
    Fitbit PROS ...
  • (Redeem Now) Download MobileXpression App And Get Rs 300 Jabong Voucher Latest Feb 2016
    MobileXpression app ...
  • Lenovo HW02 Plus fitness band Review
    Lenovo HW02 Plus ...
  • New Samsung Galaxy S7 EDGE Review: Still The Best-Looking Android Around
    In the mobile ...

Random Posts

  • Acer Swift 1 Review
    Acer Swift 1 Review
    19.01.2018 - 0 Comments
    While the Acer Swift 1 delivers what it promises—a slim and light chassis, plenty of battery life, a…
  • Flipkart Samsung Carnival
    Flipkart Samsung Carnival
    08.02.2018 - 0 Comments
    Flipkart Samsung Carnival: Samsung Galaxy S7 at Rs 22,990, Galaxy S7 edge at Rs 35,900 and other discounts…
  • PS4 seasoned vs task Scorpio: How are the mid-technology consoles shaping up?
    PS4 seasoned vs task Scorpio: How are the mid-technology consoles shaping up?
    26.03.2017 - 0 Comments
    At the moment, Sony’s PS4 Pro is comfortably the most powerful games console on the market.…
  • How to send money from paypal
    How to send money from paypal
    10.04.2017 - 0 Comments
    How to Use PayPal mass payment method? In order to send money using PayPal mass payment, you need to…
  • Gooligan Malware Roots Android to Steal Authentication Token
    Gooligan Malware Roots Android to Steal Authentication Token
    18.02.2017 - 0 Comments
    Nicknamed Gooligan, a new type of malware, has infected 1.3 million Android devices from August which was…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!