6th Oct, 2009

Pastebin.com and the Hotmail password leak

It seems that a list of 10,000 Hotmail usernames and passwords has been posted on pastebin.com in recent days.

Pastebin was created as a tool to aid software development, not to distribute this sort of material.

As a result of the interest this story is generating, pastebin.com is experiencing huge levels of activity – as a result I took it offline to ensure all the offending material has been removed, and have adjusted the abuse filters prevent re-occurence.

Edit: please don’t ask if you name was on the list. I have no way of knowing. Just change your password.

Edit #2: things have calmed down now, and I’ve written a longer post about the incident here.

Responses

has this account been posted?

I do not have a copy of the list – suggest you try searching google for your email address and see what comes up.

I suspect you’re getting a lot of traffic your way thanks to this :|

Anything I can do to ease the load? Happy to provide mirroring of your blog or pastebin, or just host a simple “pastebin is temporarily offline” message, or anything that could be useful.

ITs good to hear that, Its absoluto not fair to get troubles in our website for another person who posted that kind of information.

One question. Why I had to leave my e-mail and the password to post this comment? . . . just joking xD.

It’s so lame that you’re adding an abuse filter for this. It’s not your fault, don’t correct it.

I will replace the filter with one more specifically targeting general lists of email addresses in a few days.

its the oldes tric in the book used at my mum and told her what i did

these day’s they claim to have a bock checker
dont open the link from any1 you recieve it !!!!!!!!
i’ve you did than change your password right away

How do I know if my emailadress was on that list?! Could you post the list, without passwords, or at least the first 4 letters of the adresses to prevent abuse.

@hamids
Just change your hotmail password and you are done! It’s that easy!

Now, When I write my email in a google page, I can see my password associated with my e mail. Of course, I can’t indicate my mail but I would like to see the whole cancelation of passwords in google page.

I don’t want to enter any information about me there are hackers all around me.

Thanks for you action – it has been a good reminder to change my password more often

How do I know if my emailadress was on that list?! Could you post the list, without passwords

If you can enter in your mail now, your account is not in the list. All accounts in the list were bloqued by Microsoft.
Don’t post the liste please !!!!!!!!!!
You can make the following test if you want to know if your account is the list.
1/ Open a google windows
2/ Write your e mail adresse in the google motor search
3/ If you see your account with your password in google motor search, your account has been hacked

Somebody know if we can use our account in the future and how Microsoft can send our new password.

Many thanks and sorry for my english.

Somebody did that to my email once a while back. Why do people do such malicious things?

If you search for your full email address in google within speech marks, and see your email address displayed, then change your password and any other places you use the same password immediately.

Phishing scams have been in existence for a very long time. The very fact that this has made main stream news will be a wake up call to the nation to safeguard their passwords, and the very existence of phishing scams making people think twice about hitting reply to a phishing email.

I don’t think you should block everything… Please tell me we can still post more than just a few sentences. Deleting offending entries is probably the best answer, I’m sure theres legitimate email address lists as well. Anything can be malicious, are we going to block all programming pastes also because of a few malicious ones?? or all english stories because of illegal bestiality text porno pastes ?

The moderator has taken a very responsible action. Thumbs up to you.

I hope Microsfot Ltd. could improve its technology abilities and levels, so that they can block anyone activities on heaking the hotmail, you may imagine more and more people hope to get others password for seeking they eyes and minds. It is so terrifying thing in the world.

Actually, I feel a bit relieved that these data were published online “only”. This might mean, the addresses, telephonenumbers, etc. were not sold to fraudulent companies who would start spam- and telefone-terror on the victims.

As it is, it looks more like a big hoax, which will hopefully teach Hotmail- and MSN-Messenger-Users to not enter their emailaddresses + passwords into any friendfinders. — And specially never ever join Programs, that promise to tell them “Who Blocked You on MSN”!

wow are the man,but i think people like you will make chaos one day,if you play with fire….

I’d just like to access pastebin – I’m locked out with some nonsense message bout being referred from some link…

I will just close my account with hotmail and go somewhere else
Bye bye hotmail, and hello Gmail

me hackearon mi cuenta de hotmail no se vale quiero entrar y no puedo como puedo hacer para recuperar mi cuenta ya tengo años con ella.

[...] acceder al comunicado del Blog Pastebin por “Lordelph” ;http://blog.dixo.net/2009/10/06/pastebin-com-and-the-hotmail-password-leak/)   Para mas [...]

I all along suspected this’d happen. Microsoft and its intention of taking over the entire market forgets simple things like these! Some sould tell Bill Gates that he’s living past his expiry date!
Welcome to GMAIL ladies and gentlemen

YOU SHOULD HAVE, OR AT LEAST NOW, SHOULD, INTIMATE TO EACH AND EVERY OF THOSE HOTMAIL ACCOUNT HOLDERS WHOSE PASSWORDS YOU LEAKED OUT, EXPLANINING HOW VULNERABLE THE HOTMAIL PASSWORDS HAVE BEEN PROVED TO BE, AND THAT IT IS NONE OF YOUR INTENTION TO MISUSE THE PASSWORDS IN ANY WAY, BUT RATHER TO JUST CREATE AN INSTANCE BY WHICH YOUR DEBUGGING SERVICES ARE SHOWN TO BE PROFESSIONALLY AND TECHNICALLY SOPHISTICATED/ SUPERIOR. YOU SHOULD ALSO POINT OUT THAT IT IS NOW THE DISCRETION OF THE HOTMAIL USERS TO CONTINUE TO USE HOTMAIL (OR NOT) AND IN THE MANNER THEY WANT. INDEED IF YOU DO NOT DO THIS, I THINK YOU ARE LIABLE TO BE CALUMNISED AS ONE WHO MISUSED TECHNOLOGY FOR ‘CHEAP’ PUBLICITY YOUR SERVICES.

@Paul Krish: I have not sought any publicity and want nothing to do with this.

It is not clear to me, and it may not, I believe, to be clear to many others, whether your ‘debugging’ technology is capable of exposing only Microsoft hotmail’s vulnerability or it is “more versatile” (say capable of decoding other mail passwords such as Google as well). Should it have such a power and versatility, it would mean that all internet mailing is likely far from perfect in terms of privacy and security.

@Balumethu: my “debugging technology” is just a site where *anyone* can post a fragment of text, in a way that is useful to a programmer.

It has nothing to do with exposing email vulnerabilities.

Also, the list which is going around was generated not by “hacking” Microsoft, but by asking users for their passwords. For example, in a site which promises to tell you who is blocking you if you enter your account details.

I have had nothing to do with this list, apart from deleting it from my website as soon as I was aware it.

[...] nädalal riputati PasteBin-i tarkvaraarendusfoorumisse üles 10 000 Hotmaili parooli koos kasutajanimedega. Sellesisuline BBC [...]

Hi, lordelph, at what date you first found email-lists were posted up at pastebin? Did you delete the list immediately when you awared it? So, how long did these list be seen at pastebin then?

was this email address posted DELETED@hotmail.com

@Byron: I have no way of knowing. I don’t have the list.

@Grace: sometime between 1st and 5th Oct – I delete flagged abusive posts daily, and I certainly deleted at least one password list before the story become “news”. List was probably available for a few days.

It was the right thing to do to take the list down. Maybe people should change their passwords more often now

I am moving to gmail now :)

Phishing always struck me as being for odd people !

all emails including .com should change their passwords, .de or .it or others are safe as i know

For all the people who are migrating to Gmail…There was also a list with Gmail, Yahoo and other accounts posted on the internet (I even thought/heard this website?), so that won’t really help.

What a great discovery this site is as an aspiring programmer! yes ppl, change your passwords. Thanks for a great site Lordelph I look forward to using it =)

I can sign in to my mail inbox but I can’t get into WLM with annoying message that my contact list is not avialable plz try again l8r. any ideas?

@Byron, you are not in the list ;)

How should I know whether my hotmail was hacked?

You just have write your email adress in a google page, if your mail appears with your password in a link with the word “pastebin.com” your hotmail was hacked

Yikes – this is worrying

Omfg – couldn’t u just leave the user list alone so we could check if our account is in danger? I’m not going to change my password at my 20 gmail accounts just because the password to it can be somewhere on the Internet. I’m phishing-proof so probably my accounts r safe but I won’t change my passwords AGAIN in one week ffs.

Lordelph, are you a hacker who hacked hotmail, gmail and yahoo? ha?

me gustaria saber si me ha pasado lo ismo or q el domingo se me ffue oniendo de que me habia iniciado desd e otra ubicacion donde lo puedo saber?
donde se cambia la contraseña me lo podeeis decir ppor favorrrrrrrrrrrrr
gracias adiosssss
contestarme.

I took the advice and googled my email it appears on pastebin.ca so whilst.

i was wondering if my account on hotmail is posted?
because until moment i really do not have an account on hotmail.
i only use yahoo and gmail.
hehehehehehehe
nice jock

“was this email address posted DELETED@hotmail.com”

yes it was so change your password and quit worrying…

What is it with people not reading, Pastebin did not post the lists online, he does not have the list so cant tell you if your email address is on there, if you were stupid enough to click a link you did not know then you dont deserve to have the account in the first place

lordelph,

Sympathies for being caught in the middle of all of this; it looks like the list (and the mildly clueless follow-ups) have caused a hell of a lot of hassle for you.

On the positive side (and I am by no means implying this was intentioned!), it has increased the exposure of what appears to be a useful tool for collaborative RAD projects, so best of luck.

Lordelph has the list, he cut and paste it into a notepad document.

Edited by Lordelph/Paul Dixon: If it’s not already clear: I have no copies of the list. I want nothing to do with it.

Thankyou! Refreshing to see comments from people who “get it”!

Sigh. Last night I saw someone sent messages from my facebook account out to other people on my friend list… they left a ton of weightloss spam on people’s walls. I quickly logged on and changed my password after seeing a bunch of e-mail notifications on my phone about people wondering why I was leaving them spam. After some hours went by, I turned on the TV and saw on CNN that a bunch of accounts were compromised… so I thought mine was caught up in the incident… I went online to look for the list and it lead me here… I found a copy through Google… but oddly, mine isn’t on the list! Weird!

bognor birdman, your name and password are on the list. Change your email. Lordelph will be using it.

Edited by Lordelph/Paul Dixon: No he will not!

Wow – I would have thought that people on this website were somewhat intelligent. Think for just a minute folks.

- the passwords were obtained because the USER replied to a fake email and gave it to them

- if you have any concern that your password has been shared, then change you freakin password

- The 2nd dumbest thing I have seen here are requests to post the list – so more people can target those poor people

- The most dumbest (great english) thing is posting a specific email, so they you can then get spammed.

I just don’t get how seemingly intelligent people can not just take 3 seconds to think this through.

Midge, your name and password are on the list. Change it fast, lordelph will compromise your facebook account.

Edit by Lordelph/Paul Dixon: Grow up.

Carol Sim : I took the advice and googled my email it appears on pastebin.ca so whilst.

If lordelph had deleted the list before 6 Oct, that means the list no longer on pastebin, how can people find out their address with password via google search now?

Lordelph – I don’t understand why you took all those peoples passwords, only to spam them with your weight loss program? Does that even work?

Edited by Lordelph /Paul Dixon: It’s the only way I can pay for the secret base I’m building inside a volcano.

This site is being mirrored from the eastern block countries which shows clearly that something is hanky. Why would an open source website have a list of 10000 email addresses with pws and how do you think those passwords were acquired huh?

Edited by Lordelph / Paul Dixon: Comedy isn’t your strong point. On any other day you might be *marginally* funny. It is funny how the timewasting comments come from the same IP though…

It beats me why people go phishing

Hace dos dias me jaquearon la cuenta de hotmail, quiero saber si existe la posibilidad de recuperarla o darla de baja.

was my name on the list?

@Brock

Yes Brock, go change your password!!!!

I have seen the list online after the takedown on a service like pastebay. Anyway, guys, DO NOT STRESS … IF YOU DONT USE SERVICES TO KNOW WHO BLOCKED YOU, YOUR PASSWORD IS NOT IN THE LIST (NEITHER YOUR EMAIL)

Это огромный беспорядка, lordelph увековечивает на Google и Microsoft пользователей. Я не знаю, почему он будет делать это, если не для финансовой выгоды. lordelph действует как ни странно.

great news hahaha

this is professional tech

hahahahah go ahead

this is Microsoft gaps maybe it’s time to change on LINUX. maybe!!!

Todo cuidado é pouco!

quien quiera que haya sido el que puso las contraseñas, por favor le rogaria que me encuentre la constraseña del correo DELETED@hotmail.com, ya que es importante.

Were are the list in order to chek, please

somebody mentioned it was great that the list got published online. That is certainly very good as it rendered those e-mails safe now as their accounts are now locked and the user, as I understand, will be forced to change the password.

The only thing these users might expect is a higher volume of spam due to spam crawlers picking them up while snooping the internet – the lists are still online, albeit in limited volumes.

oh wow your filter sure did the job this time.

I just love the retards here who disregard the content of the article and just ask ‘wer is da list’ or ‘is XXX@hotmail.com on da list’. Morons!

Senhas fracas são sempre descobertas.

yeah ill be moving to gmail as well .. damn hotmail

I have three things to say!

1) LordElph/Paul Dixon had NOTHING to do with posting that list. He is the ****ing OWNER, not the USER that posted the content. I think it was very responsible to do that. What would be the point of putting other people’s (who you don’t even know) privacy at risk?

2) Microsoft was NOT ‘HACKED’. It was unknowing USERS of a Microsoft SERVICE who put their details into a website, e-mail or advert and that is how the details were got hold of.

3) @Juan: You might want to have a look at this link. http://www.stuff.co.nz/technology/digital-living/2939677/Hackers-hit-Gmail-Yahoo-too – It is NOT just hotmail users affected.

Yaaay my rant is over.
Let’s get on with life.
Case Closed.

أي شخص يمكن أن تقدم لي هذه القائمة ، أنا غير قادر على الوصول إلى حسابي هوتميل وأخشى أن LordElph هو استخدامه في فقدان الوزن حملة غير المرغوبة. LordElphin ، يرجى ارحمني والافراج عن حسابي هوتميل. أتوسل إليكم يا سيدي ، يرجى بيان حساب بريدي الإلكتروني هو DELETED@hotmail.com

Like they always say, give a man a phish and he hacks for a day, teach a man to phish and he hacks for a lifetime. ;-)

Listen dip stick, I don’t care if you don’t know if my name was on the list or not – you have a responsibility to the public because this sensitive information was posted on your lame “What does it do again” website.

Yeah! I can change my password, but what the fawk dude, then I’d have to learn a new password and we both know thats not going to happen.

So here it is, a simple solution we both can agree on GIVE ME the information that was included on that post, and I will do a very simple CRTL-F search on a text pad to find out if my hotmail account was on it or not.

No way of finding out is just another lazy man’s way of saying “I don’t care”, so just do everyone a favor and repost that post – look its real easy, you just have to stop playing world of warcraft and/or skyping with that fake potential Russian bride of yours for like two minutes, and I can go back to not having to go to lame websites and blogs like this one.

OK! THANK YOU.

Edited by Lordelph / Paul Dixon: James is clearly mentally challenged, and has my deepest sympathy.

come oooooon, pleaaaaaaase, publish the complete list again, for a second :P

I am confused as to how a password list posted on pastebin.com is responsible for pastebin.com’s spamming of a weight-loss program. Would someone help me connect point A and point B in this scenario?

Sorry but James (above) was right. I hope my post comes across better than his though.

You need to drop the attitude and get some common sense.
Clearly you scrambled to post about the story in order to get attention/hits. Then when you get the attention you wanted you start complaining because you are being criticized. (by the way Midge, that may be the reason the readers aren’t up to the usual standard..surely an intelligent person would have realised that?)

That is what happens when you put yourself out there. Do something NOT QUITE PERFECTLY and you are judged. If you can’t handle that, and feel the need to write huge follow-ups trying to get repair your self esteem or reputation.. well..you should not have a blog frankly.
I don’t see the big deal with reposting something that is already on 100 other sites (the list)
All censoring the list achieves is the poster bragging that they have the list, but they’re not going to let anyone else see it. Of course you’re going to rile people up doing that!
People naturally want to see the list, mainly to calm their anxiety over being ON the list.

Like someone else said you could have posted the email addresses WITHOUT the passwords.
That seems like the most sensible approach for all blogs and people reporting it to take…

Not just talking to you but to everyone who chooses to post stories like this without thinking it through properly.

I appreciate that when moderating comments you may have genuinely deleted the list before you realised that it would have been helpful to people coming upon your site, but common sense would tell you that the emails alone would help people immensely without exposing..well.. anything.
It is also highly unbelievable that you didn’t save the list or at least look through it yourself, so most people would assume that you are purposely withholding helpful information from them, and that DOES NOT go down well.
Fact is, people are coming to your page NOT to read about the story, but to look at/for the list. So don’t be surprised when people start bitching at you when they don’t find it. Maybe call this a lesson learned ?

It will be interesting to see if I get a smart ass comment next to my post (if it is published at all) presumably it will mention something about length, grammar or ‘getting a life’.

@Ms Me: That’s a good comment. If only all were of a similar standard!

Firstly, I “scrambled to post” because it was apparent people were coming to pastebin and had no idea what it was. Aside from the extra traffic bringing the server to a crawl, pastebin was getting stuffed full of posts with requests for the list. This wasn’t about getting attention or hits. I’ve answered only basic questions with print journalists via email, and have refused television interviews.

Neither was the longer post intended to repair self esteem or reputation, both of which are fine, thankyou. I am more than happy to take criticism, and as you’ll note in my longer post, next time I may do things differently. However I do reserve the right to poke fun at people who can’t string coherent thoughts together. You don’t fall into that category :)

As for reposting the list because its “already out there”, the answer is no. I don’t need or want the traffic or publicity. If you find it on one of the thousands of other pastebin services, feel free to post a link.

Your comment was of excellent length, grammar perfectly adequate, and I’ve no doubt you have a rich and full life :)

Oh sweet Jesus, the majority of the comments on this post make me lose faith in humanity.

About time to close comments on this one I think, that or put some bleach in the gene pool.

Luckily there are a few sensible comments, but the rest…

[...] las últimas versiones del protocolo no es posible saber quién te ha eliminado del msn? ¿Y si el leak de cuentas en pastebin, primer lugar dónde se distribuyeron las 10.000 contraseñas, no era más que un preview de [...]

[...] amable apriete llegado desde el otro lado del Atlántico, yo prefiero creer lo que Paul posteó en su blog personal: que lo bajó por el exceso de tráfico que [...]

[...] visitors, and ensuring I kept the server functioning took up all my available spare time. I wrote a short blog entry which attracted a lot of comments. Things are a little calmer now, so I’m writing this longer [...]

Hey.can u plz check if my email DELETED@hotmail.com is in the list..I cannot access my account and microsoft is not responding to my message.

Edit: Go here to recover your account: https://support.live.com/eform.aspx?productKey=wlidvalidation&ct=eformcs&scrx=1

Paul – best read I’ve had for ages…Its great to see the point in the comments where you just no longer care, maybe we could have an event when your secret base is completed… see you soon buddy, Tom

who can send me passwortd of hotmail account: valeriemarck@hotmail.fr
thanks
JJ

Useful stuff – ta

Thanks for the article, however, it seems, that there is no such file on pastebin

There are some interesting points in time in this article but I don’t know if I see all of them center to heart. There is some validity but I will take hold opinion until I look into it further. Good article , thanks and we want more! Added to FeedBurner as well

Leave a response

Your response:

Categories