Government // Cybersecurity
News
9/18/2008
04:55 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Palin E-Mail Hacker Claims Google Search Helped Find Password

Though the posted account is no longer available, some content of the Alaska governor's messages has been republished on several blog sites.

The hacker who broke into Republican vice presidential candidate Sarah Palin's Yahoo Mail account appears to have done so by requesting a password reset and answering the challenge questions with the help of Google and Wikipedia.

According to a purported first-person account of the hack posted on 4chan.org, an online forum, "Rubico," the person claiming responsibility, initiated a password change on Palin's account and then supplied the Alaska governor's birthday and her home ZIP code, with the help of "Wikipedia and Google to find the info."

That left the so-called security question: "Where did you meet your spouse?"

After further Internet searching, "Rubico" entered "Wasilla High" and was allowed to change the account's password.

Though the posted account is no longer available, it has been republished on Michelle Malkin's blog, on Wired News, and elsewhere.

The text supposedly authored by "Rubico" was supplied to Malkin by an unidentified individual who claims to have monitored the 4chan board where the discussion took place.

A determination about the authenticity of this information will fall to law enforcement officials and the legal system, if the case gets that far.

The reproduced account of the hack indicates that "Rubico" posted the changed password and screenshots from Palin's in-box to the 4chan forum. After that, others supposedly copied the information and posted it to Wikileaks and elsewhere before moderators could delete it.

According to Wired News, the handle "Rubico" has been linked by bloggers to a college student in Tennessee, whose father is a Democratic state representative.

The Register reports that Gabriel Ramuglia, the operator of the Ctunnel proxy service presumably used by "Rubico," has been contacted by the FBI and plans to provide the agency with his log files. Because one of the screenshots of Palin's Yahoo account shows part of a Ctunnelled URL, the FBI stands a good chance of figuring out the IP address of the person who took that screen shot from Ramuglia's log files.

Comment  | 
Print  | 
More Insights
Cyber Security Standards for Major Infrastructure
Cyber Security Standards for Major Infrastructure
The Presidential Executive Order from February established a framework and clear set of security standards to be applied across critical infrastructure. Now the real work begins.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest - July 22, 2014
Sophisticated attacks demand real-time risk management and continuous monitoring. Here's how federal agencies are meeting that challenge.
Flash Poll
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
A UBM Tech Radio episode on the changing economics of Flash storage used in data tiering -- sponsored by Dell.
Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.