Login Register






{Community Alert} Amazon under attack filter_list
Author
Message
{Community Alert} Amazon under attack #1
So it appears over the last few weeks that Amazon users are complaining like mad about their accounts being hacked, it appears to be from Russia with love, I think its time to enabled 2FA again.

Source/News/Proof
Doug Culp opened Amazon on his phone and this what he found ~ https://twitter.com/dougathan/status/904281983945080833
Mary ~ https://twitter.com/mary_poppin_it/statu...6709529600
Others ~ https://twitter.com/search?q=amazon%20hacked&src=typd

Now don't get me wrong I am a skeptical type of person if this is true then why is there no news reports etc unless this is another way for the Ruski's to spread a little propaganda Smile
[Image: YmmIqHV.gif]
Donations: 1CCR21K2fnu2yAinUTFPsVdY7u4FkjNPs5

[+] 2 users Like S3xySmurf's post
Reply

RE: {Community Alert} Amazon under attack #2
It's easy to bruteforce into accounts even with captcha.
All you need is DeathByCaptcha and proxies.
Also the way I break into amazon accounts is through *******(people tend to use the same passwords or similiar passwords)
what amazon really needs to do is implement a system where you are given a certain amount of attempts before your account gets locked.
(This post was last modified: 11-09-2017, 01:16 AM by Oblivious.)

[+] 1 user Likes Oblivious's post
Reply

RE: {Community Alert} Amazon under attack #3
(11-09-2017, 01:16 AM)Oblivious Wrote: It's easy to bruteforce into accounts even with captcha.
All you need is DeathByCaptcha and proxies.
Also the way I break into amazon accounts is through *******(people tend to use the same passwords or similiar passwords)
what amazon really needs to do is implement a system where you are given a certain amount of attempts before your account gets locked.

I'd have thought that Amazon would have at least by now implemented something like this but security through obscurity seems the best practice these days ...
[Image: YmmIqHV.gif]
Donations: 1CCR21K2fnu2yAinUTFPsVdY7u4FkjNPs5

[+] 1 user Likes S3xySmurf's post
Reply

RE: {Community Alert} Amazon under attack #4
(11-09-2017, 01:16 AM)Oblivious Wrote: Also the way I break into amazon accounts is through *******(people tend to use the same passwords or similiar passwords)

Absolutely so with people using the same password on multiple (If not all) accounts.

During my routine daily security tests and exploitation, I come across quite a few users who utilize the very same password on all accounts I've discovered.

(11-09-2017, 01:16 AM)Oblivious Wrote: what amazon really needs to do is implement a system where you are given a certain amount of attempts before your account gets locked.

It's called an "account lockout policy", or as some refer It as an "account lockout threshold".

I believe that every E-commerce website (and others of equal/similar Importance), should have It In place.
[Image: AD83g1A.png]

[+] 2 users Like mothered's post
Reply

RE: {Community Alert} Amazon under attack #5
I have nothing personal linked to amazon that can ruin me, so I don't give two shits, although it does suck that this is happening.
[Image: ezgif_com_gif_maker.gif]
#yellowheartsforsarah

Reply

RE: {Community Alert} Amazon under attack #6
I use Amazon a lot, most of what I buy is off Amazon.

I have a pretty strong password, but I'll change sometime soon in case this is actual an actual vulnerability.

Thanks for letting us know.


(11-02-2018, 02:51 AM)Skullmeat Wrote: Ok, there no real practical reason for doing this, but that's never stopped me.

Reply

RE: {Community Alert} Amazon under attack #7
I'm not in under attack tho, i always change my password at every 1month Wink

[+] 1 user Likes hackedia's post
Reply

RE: {Community Alert} Amazon under attack #8
(11-09-2017, 04:46 PM)hackedia Wrote: I'm not in under attack tho, i always change my password at every 1month  Wink

It's a good policy to have if your not lazy, I just use my phone as a secondary security device mainly but I've had a few alerts over the last few months where 10 yr old dead accounts have bee re-activated but then again my security policy sucked balls back in the day.
[Image: YmmIqHV.gif]
Donations: 1CCR21K2fnu2yAinUTFPsVdY7u4FkjNPs5

[+] 1 user Likes S3xySmurf's post
Reply

RE: {Community Alert} Amazon under attack #9
(11-09-2017, 05:02 PM)S3xySmurf Wrote:
(11-09-2017, 04:46 PM)hackedia Wrote: I'm not in under attack tho, i always change my password at every 1month  Wink

It's a good policy to have if your not lazy, I just use my phone as a secondary security device mainly but I've had a few alerts over the last few months where 10 yr old dead accounts have bee re-activated but then again my security policy sucked balls back in the day.
Well i always use 2 factor authentication with a complex password and if 2fa is not enabled on site then i make complex password with mixing some CAPITALsmallNUMBERScharacters etc and i save all information to a encrypted locked usb that are bind in my laptop cable Biggrin
it only takes some minutes to change once in a month, so it's not bad tho Biggrin

Reply

RE: {Community Alert} Amazon under attack #10
2 factor authentication is always a great idea.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

[+] 1 user Likes Oni's post
Reply