More details on how the hacker managed to break in VP candidate Sarah Palin emerged. The hacker who calls himself “rubico” posted on a blog on the methods he used to break into the account.

He says he used a loop hole in simple password reset module in Yahoo mail. He managed to answer the secret question which Palin used while registering at yahoo. Usually websites ask for pets name, fathers middle name etc. For a vice president candidate these details are available online at the click of the mouse.

The hacker managed to answer

  1. Sarah’s birthday by looking at Wikipedia
  2. Where she met her spouse. Took a while to answer but eventually ‘Wasilla High School’ allowed him him
  3. Zip code : Alaska had only two
  4. Alternative email address : Still unclear on how he managed to read the password reset link email
  5. Hacker reset the password to ‘popcorn’

Both account used Sarah Plain were hacked ([email protected] ; [email protected]) and now deleted.

20-year-old University of Tennessee student has been questioned in connection to the federal investigation of the break-in while the online community accuses Palin of using webmail services such as yahoo to do the official business.

Wikileaks has earlier published the screenshot of sarah’s email account and contacts and is available for download in zip format here

http://wikileaks.org/wiki/Sarah_Palin_Yahoo_account_2008

Sarah Palins email

Sarah Palin’s email

Sarah Palins Inbox

Sarah Palin’s Inbox

Explore More

LDAP Injection Vulnerabilities

LDAP Injection Overview LDAP Injection attacks are not as common as the other types of injection attacks, but if your product uses an LDAP server this must be tested. An

Expert Tips for Keeping Google Hacks at Bay

The first step for protecting yourself from something is knowing how that something works. In the case of Google hacking, you will have to learn how it can be used

Critical SQL Injection and XSS Vulnerability in Myanmar Engineering Society

PlanetCreator has reported another critical SQL Injection (vulnerability) on Myanmar Engineering Society Website http://www.mes.org.mm SQL injection is a code injection technique that exploits a security vulnerability occurring in the database