Sinisterly
{Community Alert} Amazon under attack - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: General (https://sinister.li/Forum-General)
+--- Forum: The Lounge (https://sinister.li/Forum-The-Lounge)
+--- Thread: {Community Alert} Amazon under attack (/Thread-Community-Alert-Amazon-under-attack)

Pages: 1 2


{Community Alert} Amazon under attack - S3xySmurf - 11-09-2017

So it appears over the last few weeks that Amazon users are complaining like mad about their accounts being hacked, it appears to be from Russia with love, I think its time to enabled 2FA again.

Source/News/Proof
Doug Culp opened Amazon on his phone and this what he found ~ https://twitter.com/dougathan/status/904281983945080833
Mary ~ https://twitter.com/mary_poppin_it/status/904566496709529600
Others ~ https://twitter.com/search?q=amazon%20hacked&src=typd

Now don't get me wrong I am a skeptical type of person if this is true then why is there no news reports etc unless this is another way for the Ruski's to spread a little propaganda Smile


RE: {Community Alert} Amazon under attack - Oblivious - 11-09-2017

It's easy to bruteforce into accounts even with captcha.
All you need is DeathByCaptcha and proxies.
Also the way I break into amazon accounts is through *******(people tend to use the same passwords or similiar passwords)
what amazon really needs to do is implement a system where you are given a certain amount of attempts before your account gets locked.


RE: {Community Alert} Amazon under attack - S3xySmurf - 11-09-2017

(11-09-2017, 01:16 AM)Oblivious Wrote: It's easy to bruteforce into accounts even with captcha.
All you need is DeathByCaptcha and proxies.
Also the way I break into amazon accounts is through *******(people tend to use the same passwords or similiar passwords)
what amazon really needs to do is implement a system where you are given a certain amount of attempts before your account gets locked.

I'd have thought that Amazon would have at least by now implemented something like this but security through obscurity seems the best practice these days ...


RE: {Community Alert} Amazon under attack - mothered - 11-09-2017

(11-09-2017, 01:16 AM)Oblivious Wrote: Also the way I break into amazon accounts is through *******(people tend to use the same passwords or similiar passwords)

Absolutely so with people using the same password on multiple (If not all) accounts.

During my routine daily security tests and exploitation, I come across quite a few users who utilize the very same password on all accounts I've discovered.

(11-09-2017, 01:16 AM)Oblivious Wrote: what amazon really needs to do is implement a system where you are given a certain amount of attempts before your account gets locked.

It's called an "account lockout policy", or as some refer It as an "account lockout threshold".

I believe that every E-commerce website (and others of equal/similar Importance), should have It In place.


RE: {Community Alert} Amazon under attack - Synthx - 11-09-2017

I have nothing personal linked to amazon that can ruin me, so I don't give two shits, although it does suck that this is happening.


RE: {Community Alert} Amazon under attack - Blink - 11-09-2017

I use Amazon a lot, most of what I buy is off Amazon.

I have a pretty strong password, but I'll change sometime soon in case this is actual an actual vulnerability.

Thanks for letting us know.


RE: {Community Alert} Amazon under attack - hackedia - 11-09-2017

I'm not in under attack tho, i always change my password at every 1month Wink


RE: {Community Alert} Amazon under attack - S3xySmurf - 11-09-2017

(11-09-2017, 04:46 PM)hackedia Wrote: I'm not in under attack tho, i always change my password at every 1month  Wink

It's a good policy to have if your not lazy, I just use my phone as a secondary security device mainly but I've had a few alerts over the last few months where 10 yr old dead accounts have bee re-activated but then again my security policy sucked balls back in the day.


RE: {Community Alert} Amazon under attack - hackedia - 11-09-2017

(11-09-2017, 05:02 PM)S3xySmurf Wrote:
(11-09-2017, 04:46 PM)hackedia Wrote: I'm not in under attack tho, i always change my password at every 1month  Wink

It's a good policy to have if your not lazy, I just use my phone as a secondary security device mainly but I've had a few alerts over the last few months where 10 yr old dead accounts have bee re-activated but then again my security policy sucked balls back in the day.
Well i always use 2 factor authentication with a complex password and if 2fa is not enabled on site then i make complex password with mixing some CAPITALsmallNUMBERScharacters etc and i save all information to a encrypted locked usb that are bind in my laptop cable Biggrin
it only takes some minutes to change once in a month, so it's not bad tho Biggrin


RE: {Community Alert} Amazon under attack - Oni - 11-09-2017

2 factor authentication is always a great idea.