Don't forget local compromises - keyloggers, spyware, and other malware -
running on an end-user's system.

If you are checking your email with an email client and not entering your
password every time you check for mail (which most of us don't do) then the
password to your email is stored some where locally on your system.  A
crafted piece of malware can get the password that way.

If you're checking your email via webmail and you're not typing in your
password every time you log in, i.e. it's stored in your browser... then
the password is stored some where locally on your system.  A crafted piece
of malware could find that password as well.

On Wed, Nov 17, 2021 at 11:21 AM John Levine via mailop <mailop@mailop.org>
wrote:

> It appears that Bill Cole via mailop <mailop@mailop.org> said:
> >Who needs to bother with brute force "cracking" when so many passwords
> >are just out there for the taking?
>
> Botnets.  My MTA accepts any login, says it works, and directs any
> subsequent mail
> to the spamtrap.  Here's attempts from the last 20 minutes.  Some of those
> logins
> are related to actual addresses here, some are just random.
>
> 2021-11-17 11:55:34.713814500 mailfront[19253]: Fake login hsttbhpvx /
> hsttbh123
> 2021-11-17 11:55:59.927913500 mailfront[19323]: Fake login leonard@c /
> leonar123
> 2021-11-17 11:57:13.664694500 mailfront[19603]: Fake login bob2@bob /
> bob22020
> 2021-11-17 11:57:19.972595500 mailfront[19614]: Fake login webmaster /
> webmas123
> 2021-11-17 11:57:24.721663500 mailfront[19622]: Fake login mcknight. /
> mcknig123
> 2021-11-17 11:57:49.227991500 mailfront[19676]: Fake login 1993jul19 /
> 1993ju123
> 2021-11-17 11:57:59.733940500 mailfront[19696]: Fake login saudadesd /
> saudad123
> 2021-11-17 11:58:32.167072500 mailfront[19806]: Fake login dofcowsou /
> dofcow123
> 2021-11-17 11:58:48.499845500 mailfront[19849]: Fake login xxuqtby@l /
> xxuqtb123
> 2021-11-17 11:59:15.775566500 mailfront[19933]: Fake login larisaxdv /
> larisa123
> 2021-11-17 11:59:19.308656500 mailfront[19937]: Fake login stratfor@ /
> stratf123
> 2021-11-17 11:59:27.927226500 mailfront[19960]: Fake login areferker@iec
> / areferker2020
> 2021-11-17 11:59:40.918734500 mailfront[20024]: Fake login postmaste /
> postma123
> 2021-11-17 11:59:55.085884500 mailfront[20061]: Fake login spayeddbe /
> spayed123
> 2021-11-17 12:01:19.801787500 mailfront[20349]: Fake login bobrisks@bob /
> bobrisks2020
> 2021-11-17 12:01:28.290702500 mailfront[20362]: Fake login asrg@joh /
> asrg2020
> 2021-11-17 12:02:13.205276500 mailfront[20537]: Fake login bobf@fra /
> bobf2020
> 2021-11-17 12:02:22.114495500 mailfront[20581]: Fake login airliners /
> airlin123
> 2021-11-17 12:02:52.691619500 mailfront[20704]: Fake login postmaste /
> postma123
> 2021-11-17 12:03:25.757517500 mailfront[20839]: Fake login postmaste /
> postma123
> 2021-11-17 12:03:47.168752500 mailfront[20891]: Fake login jonathon@ /
> jonath123
> 2021-11-17 12:04:03.789002500 mailfront[20934]: Fake login info@zeu /
> password
> 2021-11-17 12:04:15.674974500 mailfront[20970]: Fake login obnoxious /
> obnoxi123
> 2021-11-17 12:04:57.635122500 mailfront[21150]: Fake login kseniyawx /
> kseniy123
> 2021-11-17 12:05:18.170965500 mailfront[21242]: Fake login xwmhdral@ /
> xwmhdr123
> 2021-11-17 12:05:36.038108500 mailfront[21305]: Fake login asrg@bob /
> asrg2020
> 2021-11-17 12:07:38.065773500 mailfront[21776]: Fake login as@zeu / as2020
> 2021-11-17 12:08:00.444663500 mailfront[21851]: Fake login aalter@bobf /
> aalter@1234
> 2021-11-17 12:08:05.554393500 mailfront[21858]: Fake login andrewjnash@iec
> / andrewjnash2020
> 2021-11-17 12:08:08.867614500 mailfront[21872]: Fake login anna12550@zeu
> / anna125502020
> 2021-11-17 12:08:30.686983500 mailfront[21995]: Fake login approval@iec /
> approval2020
> 2021-11-17 12:08:52.278898500 mailfront[22082]: Fake login arsenii@iecc /
> arsenii@1234
> 2021-11-17 12:09:10.315914500 mailfront[22140]: Fake login yuliafrwy /
> yuliaf123
> 2021-11-17 12:09:42.345135500 mailfront[22207]: Fake login postmaste /
> postma123
> 2021-11-17 12:10:08.705233500 mailfront[22327]: Fake login atlantic@ /
> atlant123
> 2021-11-17 12:11:16.344928500 mailfront[22478]: Fake login pistols@c /
> pistol123
> 2021-11-17 12:11:29.804099500 mailfront[22512]: Fake login webmaster /
> webmas123
> 2021-11-17 12:11:55.193699500 mailfront[22605]: Fake login bobmarly@bob /
> bobmarly2020
> 2021-11-17 12:12:25.315811500 mailfront[22690]: Fake login travelmol /
> travel123
> 2021-11-17 12:12:25.576148500 mailfront[22675]: Fake login approve@tel /
> approve2020
> 2021-11-17 12:12:48.556795500 mailfront[22734]: Fake login 299.13@ /
> 13@1234
> 2021-11-17 12:13:45.074059500 mailfront[22933]: Fake login costcentr /
> costce123
> 2021-11-17 12:14:57.807258500 mailfront[23156]: Fake login barryjoe0 /
> barryj123
> 2021-11-17 12:16:11.739180500 mailfront[23449]: Fake login alison@iec /
> alison2020
> 2021-11-17 12:16:15.895229500 mailfront[23482]: Fake login shannoncb /
> shanno123
> 2021-11-17 12:16:30.859248500 mailfront[23659]: Fake login as1994oct /
> as1994123
> 2021-11-17 12:16:57.007395500 mailfront[23691]: Fake login isocmembe /
> isocme123
> 2021-11-17 12:17:04.555398500 mailfront[23713]: Fake login hopkins@c /
> hopkin123
> 2021-11-17 12:17:11.761031500 mailfront[23733]: Fake login hostmaste /
> hostma123
> 2021-11-17 12:18:10.497572500 mailfront[23944]: Fake login hostmaster@ /
> Hostma12345
>
> I agree that reuse and phishing are likely to be more productive.
>
> R's,
> John
> _______________________________________________
> mailop mailing list
> mailop@mailop.org
> https://list.mailop.org/listinfo/mailop
>
_______________________________________________
mailop mailing list
mailop@mailop.org
https://list.mailop.org/listinfo/mailop

Reply via email to