Hackers claim $10,000 prize for breaking into StrongWebmail

By Robert McMillan, IDG News Service |  Security, authentication, email 1 comment

Hackers love a challenge. And more than that, they love cash.

That's what Telesign found out this week. A provider of voice-based authentication software, the company challenged hackers to break into its StrongWebmail.com Web site late last week. The prize? US$10,000.

On Thursday, a group of security researchers claimed to have won the contest, which challenged hackers to break into the Web mail account of StrongWebmail CEO Darren Berkovitz and report back details from his June 26 calendar entry.

The hackers, led by Secure Science Chief Scientist Lance James and security researchers Aviv Raff and Mike Bailey, provided details from Berkovitz's calendar to IDG News Service. In an interview, Berkovitz confirmed those details were from his account.

However, Berkovitz could not confirm that the hackers had actually won the prize. He said he would need to check to confirm that the hackers had abided by the contest rules, adding, "if someone did it, we'll kind of put our heads down," he said.

Contest rules prevent the researchers from disclosing how they performed their attack, but they were also able to compromise a test StrongWebmail account set up by IDG News Service. The IDG attack did not work initially, but succeeded when security software called NoScript was disabled on the Firefox browser, running on a Windows XP machine.

"We found multiple cross-site attacks that allow us to attack other users," James said. "You have to have a registered account to launch the attack."

StrongWebmail uses Telisign's telephone authentication system to give webmail users another layer of security. Instead of logging in with a username and password, customers must also enter a secret code that gets telephoned to them whenever they want to log into the site.

Banks have been using these phone-based authentication servers to help fight cybercriminals who often steal usernames and passwords from victims.

But this kind of authentication -- called two-factor authentication -- can be thwarted by hackers using what's known as a man-in-the middle attack. In this attack, the hacker's software waits for the user to legitimately log into the Web site and then takes over. "They just wait for you to log in and they can do whatever they want," James said.

James said that these contests might be fun, but they don't provide a realistic measure of real security because they are encumbered with rules. The StrongWebmail contest prohibits working with a company insider, for example. "A bad guy won't care about rules, he said.

Webmail security has gotten a lot of attention over the past year. In September a hacker gained access to Alaska Governor Sarah Palin's e-mail account and published details of her correspondence on the Internet. A college student named David Kernell has been charged in that incident.

Whatever the contest's outcome, Berkovitz says he hopes his contest gets users -- and webmail providers like Google and Yahoo -- thinking more about security. "We're not claiming that this is the ultimate, ultimate solution," he said. "But we're trying to bring attention to the username and password portion."

1 comment

    Anonymous 45 weeks ago
    $2 = 1 Random Visa USA$3 = 1 Visa USA can pay verify paygate$2 = 1 Random master USA$3 = 1 Master USA can pay verify paygate$3 = 1 Amex USA$4 = 1 Discovery USA$40= track1and2$60=EUROPE TRACK 1&2$15=mailer with boxMy LR acc: U6257457First name: tuyetLast name: hangCity: ZlatoustRussian Federationwww.vbv_visa.iwannaforum.comtuyet_hang12345@yahoo.comICQ number: 498347810www.tuyet-hang12345.myopenid.com4547426793372235=10092010000010870000 [2936] 4547424008265401=09112010000029710000 [3249]5533901088001908=12111011853375727160 LUFTHANSA AIRPLUS SERVICEKARTEN GMBH GERMANY5533901088124312=12111011822749300690 LUFTHANSA AIRPLUS SERVICEKARTEN GMBH GERMANY5533901088545599=12111011809843293880 LUFTHANSA AIRPLUS SERVICEKARTEN GMBH GERMANY==LIVE==1269

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      Overcome Top 7 Admin Challenges of Active Directory

      As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

      White Paper

      Insiders Can Ruin Your Company. Take Action.

      Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

      White Paper

      Top Solutions and Tools to Prevent Devastating Malware

      Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

      White Paper

      Streamline Compliance and Increase ROI

      Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

      White Paper

      X-Ray of the PCI Process-4 Proactive Steps

      This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question