News: 1599815230

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Three middle-aged Dutch hackers slipped into Donald Trump's Twitter account days before 2016 US election

(2020/09/11)


Three “grumpy old hackers” in the Netherlands managed to access Donald Trump’s Twitter account in 2016 by extracting his password from the 2012 Linkedin hack.

The pseudonymous, middle-aged chaps, named only as Edwin, Mattijs and Victor, told reporters they had lifted Trump’s particulars from a database that was being passed about hackers, and tried it on his account.

To their considerable surprise, the password – but not the email address associated with @realdonaldtrump – worked the first time they tried it, with Twitter’s login process confirming the password was correct.

The explosive allegations were [1]made by Vrij Nederland (VN) , a Dutch magazine founded during WWII as part of the Dutch resistance to Nazi German occupation.

“A digital treasure chest with 120 million usernames and hashes of passwords. It was the spoil of a 2012 digital break-in,” wrote VN journalist Gerard Janssen, describing the LinkedIn database hack. After the networking website for suits was [2]hacked in 2012 by [3]a Russian miscreant , the database found its way [4]onto the public internet in 2016 when researchers eagerly pored over the hashes. Critically, the leaked database included 6.5 million hashed but unsalted passwords.

Poring through the database, the trio found an entry for Trump as well as the hash for Trump’s password: 07b8938319c267dcdb501665220204bbde87bf1d. Using John the Ripper, a hash-reversing tool, they were able to uncover one of the Orange One’s login credentials. Some considerable searching revealed the correct email address (twitter@donaldjtrump.com – a different one from the one Trump used on LinkedIn and which was revealed in the hack)… only for the “middle aged” hackers to be defeated by Twitter detecting that the man who would become the 45th president of the United States had logged in earlier from New York.

One open proxy server later, they were in.

VN published screenshots supplied by the three showing a browser seemingly logged into Trump’s Twitter account, displaying a tweet dating [5]from 27 October 2016 referring to a speech Trump delivered in Charlotte, North Carolina, USA.

The Dutch hackers also alleged that they found Trump’s details in a database hacked from Ashley Madison, a dating website aimed at cheating spouses. Amusingly, [6]just 1.4 per cent of its 31 million users were actual women .

Despite trying to alert American authorities to just how insecure Trump’s account was (no multi-factor authentication, recycled password from an earlier breach) the hackers’ efforts got nowhere, until in desperation they tried Netherland’s [7]National Cyber Security Centrum – which acknowledged receipt of their prepared breach report, which the increasingly concerned men had prepared immediately once they realised their digital trail was not particularly well covered.

“In short, the grumpy old hackers must set a good example. And to do it properly with someone they 'may not really like' they think this is a good example of a responsible disclosure, the unsolicited reporting of a security risk,” concluded VN’s Janssen.

Professor Alan Woodward of the University of Surrey added: “It’s password hygiene 101: use a different password for each account. And, if you know a password has been compromised in a previous breach (I think LinkedIn is well known) then for goodness sake, don’t use that one.

This is

a textbook example of credential stuffing.” ®

Get our [8]Tech Resources



[1] https://www.vn.nl/hackers-twitter-trump/?token=b3lvemtSUGhpL3Y3ckNtMnd1TjVJTHN4THJNenQ1UnBvV0xZM3p5SlNWMD0

[2] https://www.theregister.com/2012/06/07/linkedin_admits_data_breach/

[3] https://www.theregister.com/2020/04/28/linkedin_dropbox_hacking_trial/

[4] https://www.theregister.com/2016/05/24/linkedin_password_leak_hack_crack/

[5] https://twitter.com/realDonaldTrump/status/791762650195632128

[6] https://www.theregister.com/2015/08/27/ashley_madison_men/

[7] https://www.ncsc.nl/

[8] https://whitepapers.theregister.com/

Alister

To be fair, they could have guessed "password1" without having to resort to the LinkedIn breach...

Grease Monkey

What makes you think it was that complex?

But

Anonymous Coward

Is "Putin" long enough to be a proper password?

Need better pseudonyms

Chairman of the Bored

Might I suggest "Dewey, Screwum, and Howe?"

With apologies to the entire legal profession.

In all seriousness, well done gentlemen.

Re: Need better pseudonyms

chivo243

A popular poster for The Three Stooges features the Stooges as bumbling members of such a firm, although the actual episodes use the name "Dewey, Burnham, and Howe".

Re: Need better pseudonyms

Symon

I think they're known as Sue, Grabbit and Runne in Britain!

https://en.wiktionary.org/wiki/Sue,_Grabbit_and_Runne

And if you have any doubt

Steeev

Use https://haveibeenpwned.com/

Re: And if you have any doubt

Pascal Monett

Yeah, but there's one problem with that : it will report your email as having been hacked even after you've just reset the password.

So I have no idea now if my new password has been breached.

Re: And if you have any doubt

MatthewSt

https://haveibeenpwned.com/Passwords - you can check your password in there (or if you don't trust the write up about how the passwords aren't submitted you can download the full list and check it yourself)

Re: And if you have any doubt

lglethal

I just tested with my email address and it does say when the breach was at least discovered. So if you're password was changed more recently then the latest email breach, you are probably safe.

I say Probably, because haveibeenpwned only know about the breaches that have been discovered after all... ;)

Funnily enough, my email address ended up in the breach for the game EVONY. I've never heard of the game, let alone played it so buggered if I know how that happened, but it just goes to show that your email will turn up everywhere on the internet, even in places you never would have expected...

Enter the hash into a search engine ...

alain williams

and I got to [1]an article in Dutch at the bottom of which it claims that the orange one's password is YOUREFIRED . We can only hope that that will become true in a few months time.

[1] https://www.vn.nl/tijdlijn-zo-verliep-de-hack-van-trump/

Re: Enter the hash into a search engine ...

Anonymous Coward

Given the democrats are currently telling Biden to repeat everything Trump said two months ago, whilst panic-publishing policies that are just Trump's law'n'ordah rhetoric with the serial numbers filed off, I suspect their internal polling shows a growing support for Trump that they didn't anticipate, and I further suspect that he will take home a win in November.

Re: Enter the hash into a search engine ...

Symon

I heard on Radio 4 once an American political commentator saying that Democratic Party politicians are great at forming a firing squad for their opponents. Their only problem is that they stood in a circle...

If you check on https://crackstation.net/ (as I just did, as I was curious)

goldcd

That would appear to be correct input to SHA1 the hash in the article.

I can't believe that was his password though.. even Trump wouldn't...

Re: If you check on https://crackstation.net/ (as I just did, as I was curious)

Katy_B

Oh yes he did. I'm guessing he's updated it now though. Maybe try 'Ivankashot'?

What can be said?

chivo243

Go Cloggies! Klever Klompen!

Fake Tweats Would Have Been Obvious

Anonymous Coward

especially if they made sense.

Fake news

Katy_B

Listen, Trump is a stable genius who doesn't need advice from a bunch of computer nerds. Let him be with his passwords.

And if a bunch of computer nerds hack his twitter again could they please make sure to put in his thoughts on 'losers' who get killed fighting wars.

Please??

Real Programmers think better when playing Adventure or Rogue.