How to check if your email password has been compromised (1 Viewer)

Jon

Access World Site Owner
Staff member
Local time
Today, 03:02
Joined
Sep 28, 1999
Messages
4,954
This has become an important issue for me because I have found multiple of my email addresses have been hacked. Look what Google told me:

1614174601968.png


So, I highly recommend you check yours.

Go here and let us know your results: https://haveibeenpwned.com/
 

NauticalGent

CopyPaster of the First Order
Local time
Yesterday, 22:02
Joined
Apr 27, 2015
Messages
3,720
This site was introduced to me while I was being "onboarded" at my new employer. Highly recommended by our IT/Security VP's.

I was happy and relived to see that I had not been "pwned"!
 

Jon

Access World Site Owner
Staff member
Local time
Today, 03:02
Joined
Sep 28, 1999
Messages
4,954
Lucky you! It is going to take me a long long time to update over 200 passwords!!
 

Jon

Access World Site Owner
Staff member
Local time
Today, 03:02
Joined
Sep 28, 1999
Messages
4,954
Knot funny.

One a day...by the time I get to the 200th password they will have hacked the first ones again!

I have a Wordpress site that was hacked. I've rescured it and deleted all the malicious files twice in the last few days. They keep hacking it but I don't know how they are getting through. I've got a security plugin on there, changed passwords and so on. Yesterday I delted about 5 malicious files. Today, there was about 20!
 

Isaac

Lifelong Learner
Local time
Yesterday, 19:02
Joined
Mar 14, 2017
Messages
5,148
I got lucky. Experian (credit reporting agency) recently advised me that one of my most oft-used passwords had been hacked.
I guess I'm not sure which is worse. Finding out 200 of yours had been hacked, or finding out one that you used in 200 places has been hacked. I guess either way we have a lot of resetting to do. I haven't started mine yet, to be totally honest
 

Gasman

Enthusiastic Amateur
Local time
Today, 03:02
Joined
Sep 21, 2011
Messages
8,294
Well it would be useful if they told you where, what site?
 

The_Doc_Man

Immoderate Moderator
Staff member
Local time
Yesterday, 21:02
Joined
Feb 28, 2001
Messages
20,006
The interesting result is that I have 1 site - but my e-mail password was one that my vendor generated for me because I'm on an older version of Outlook that can't do the newer security stuff. I'll have to check what it takes to change that one.
 

AccessBlaster

Registered User.
Local time
Yesterday, 19:02
Joined
May 22, 2010
Messages
3,765
I like the fact you give them your information first, then they tell you why yes you are infected!
 

Jon

Access World Site Owner
Staff member
Local time
Today, 03:02
Joined
Sep 28, 1999
Messages
4,954
The truth of the matter is that all sites are hammered constantly. I checked some of my sites that get very little traffic and I have neglected because they are old projects I no longer have any interest in. They are just about all hammered. One site was hacked and they put a link in the footer of the site, so that my copyright notice actually linked out to their pharma site, or whatever it was.

I guess either way we have a lot of resetting to do. I haven't started mine yet, to be totally honest

The reason I believe my own hacks will have little impact on your security is because:

1. This forum has a strong unique password.

2. If they did manage to hack the site, you cannot see any passwords from the software.

3. The software checks all files daily to see if there are any anomalies. There have never been any anomalies. (This does not apply to the old vBulletin site, which became insecure with age. That was one of the reasons we upgraded to Xenforo.)

1614248866953.png


4. If the someone get access to my hosting account, you can look at raw data using phpmyadmin. But all the passwords are encrypted.

5. WordPress is up to date on this site and has security software installed on it. A recent scan shows no changes to the files or non_WordPress files.

6. There are currently no known exploits on Xenforo.

Doc, are you saying that your email password was flagged as being hacked?

Please note that the data shown on haveibeenpwned doesn't show the number of sites hacked or passwords leaked, because I imagine most are done by bots and never make it to any list at all.

Curious if anybody else reading this thread has had adverse results from the haveibeenpwned site?

Edit: Just so you can see the Wordpress check:

1614254054836.png
 
Last edited:

Gasman

Enthusiastic Amateur
Local time
Today, 03:02
Joined
Sep 21, 2011
Messages
8,294
They do tell you.

I like the fact you give them your information first, then they tell you why yes you are infected!
I tried my partime work address and that cam back clean.
My Google always warns me as Jon showed at the start

I saw a list at the bottom of the page, but most I'd never heard of, let alone used my email address on. I had Creative and dropBox out of 9 breaches?
 

Jon

Access World Site Owner
Staff member
Local time
Today, 03:02
Joined
Sep 28, 1999
Messages
4,954
I had Creative and dropBox out of 9 breaches?
Do you mean that the tools showed 9 breaches in total for you?

The 267 compromised passwords I had...to be frank, I cannot believe I am signed up to that many sites. I have yet to work my way through that list because I am in a battle with a hacker who keeps hacking one of my WordPress sites day after day. I'm hoping I have solved it now because I found another hidden file that the security software did not pick up. Only time will tell. Perhaps I have 267 compromised passwords because maybe once they get your data, they used your email and password to join lots of other sites too. Who knows?
 

Gasman

Enthusiastic Amateur
Local time
Today, 03:02
Joined
Sep 21, 2011
Messages
8,294
because maybe once they get your data, they used your email and password to join lots of other sites too. Who knows?
Wouldn't you get the emails then though?

With Gmail, if I go to a friend's house to look after their dogs, I get a warning email that someone is accessing my mail from another ip address.? Most times, the access is blocked until I confirm it is me or not.?

Used to annoy the hell out of me when I went on holiday in Mexico :D
 

Jon

Access World Site Owner
Staff member
Local time
Today, 03:02
Joined
Sep 28, 1999
Messages
4,954
Wouldn't you get the emails then though?
You could be right. When I go through the list I will find out why I have so many passwords or if the message is misleading. it seems a rather large number though!
 

Jon

Access World Site Owner
Staff member
Local time
Today, 03:02
Joined
Sep 28, 1999
Messages
4,954
My God, it's worse than I thought! I must spend less time on the internet. :eek:

1614254925645.png
 

NauticalGent

CopyPaster of the First Order
Local time
Yesterday, 22:02
Joined
Apr 27, 2015
Messages
3,720
Holy Shit, Batman! You need a few more hobbies....maybe cliff jumping or repelling, your knot tying hobby would dovetail nicely!
 

Gasman

Enthusiastic Amateur
Local time
Today, 03:02
Joined
Sep 21, 2011
Messages
8,294
My God, it's worse than I thought! I must spend less time on the internet. :eek:

View attachment 89518
Not really :)
To get a lot of info these days, you have to register. You do so, look for what you need, and might never go back there again?
The sites make you do that. I can count on my fingers of both hands the sites I use regularly :)
 

Jon

Access World Site Owner
Staff member
Local time
Today, 03:02
Joined
Sep 28, 1999
Messages
4,954
Holy Shit, Batman! You need a few more hobbies....maybe cliff jumping or repelling, your knot tying hobby would dovetail nicely!
I might learn a hangman's noose next at this rate.
 

AccessBlaster

Registered User.
Local time
Yesterday, 19:02
Joined
May 22, 2010
Messages
3,765
I tried my partime work address and that cam back clean.
My Google always warns me as Jon showed at the start
I tried my accessblaster email and it was clean, I am hesitant to give them my daily driver.;)
 

Users who are viewing this thread

Top Bottom