PDA

View Full Version : Hotmail Hashes



AcroMace
01-29-2009, 02:45 AM
Alright first of all, I'm not asking anyone to hack an account for me or offering to hack one for them...

I'm just learning about hashes, and how they work.
I know that Hotmail never really stores the plaintext passwords, but encrypts them into hashes.
If you click "Save my User ID and Password" while logging into Hotmail,
then it saves the information as cookies on your computer,
and I'm guessing that the encrypted hash is saved somewhere in the file.

One of the reasons I'm pretty sure it's saved on it is because that sidejacking works,
and I'm going to guess everyone that's not going to spam on this thread knows what that means.

Then wouldn't it be theoretically possible for someone to hack into your computer,
transfer than log in cookie to their computer,
then use some hash crackers to get a shot at the hash and get the password?

I mean, with the extremely fast speed of those rainbow tables, I'm pretty sure it wouldn't even take that long to crack the password.

Can anyone tell me the flaw of this theory which I'm not understanding?

Moonbat
01-29-2009, 08:56 AM
The cookie does not contain your password hash; rather it contains a session ID that is linked to your account. Someone can steal your cookie and get access to your session. You can easily log out and log back in to create a new session, if for any reason a hacker gets your cookie.

AcroMace
01-30-2009, 01:22 AM
Oh, so they create a session ID that gets reset everytime you log in and log out.
I also heard that you have to be on the same IP for the session ID to be valid.

Then that doesn't exactly work for Hotmail... but what about Yahoo! and Gmail?

I know that the cookie stealing worked for Yahoo! about *-2 years ago, has it been patched already?

Moonbat
01-30-2009, 04:36 PM
There are no publicly-known ways to steal cookies at the moment. But I bet my left foot that there are privately-known methods of cookie stealing being used by more underground hackers.

Yahoo! and Gmail work the same way as Hotmail. None of the big three mail services store passwords in the cookies.

simrnz
02-03-2009, 06:24 AM
yeah, I'm not too good at hacking but this thing me too pretty sure that none of the yahoo, gtalk and MSN record passwords in the cookies.

erkan17
02-03-2009, 10:09 AM
Can someone please tell me a program for hacking .I downloaded alot of softwares but none of them work. I just want to hack or get my girlfriends Hotmail password. So can someone please tell me how or send me a link with a good program for hacking?. The email is bronwynwilliamson@hotmail.com if anyone can find out the password and tell me it would be greatly appreciated.