Menu
Reply
Highlighted
  • 18
  • 0
  • 1
krispy
Tuning in
308 Views
Message 1 of 14
Flag for a moderator

NTLWorld e-mail account passwords on the net - account being abused

Hi there,

I've got a serious problem with my e-mail account, and now I cannot get into my profile area on the virgin website (error screen appears trying to get into any account/profile areas).

I noticed a lot of error e-mails from [REMOVED]@virginmedia.com - an example (there are lots - different ips, different destination e-mail addresses);

-----

This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed permanently:

* [REMOVED]@yahoo.com

Reason: This is the mail system at host know-smtprelay-1-imp.

I am sorry to have to inform you that your message, "Watch multiplicity entirety exposition fjuljs E0C7ED07-remfg", could not be delivered to [REMOVED]@yahoo.com.

Messages from your IP have been determined to be suspicious as a device on your current network may have malware. Please refer to the spamhaus listing below for further infomation;

https://www.spamhaus.org/query/ip/212.66.113.100


Please be aware that if you are not sending mail from your own broadband connection that the listing may have been caused by a previous user The remote server returned the below error when attempting delivery:

554:554 delivery error: dd Requested mail action aborted - mta4154.mail.ne1.yahoo.com

--------

 

So I checked https://haveibeenpwned.com/  only to find this is available online; https://pastebin.com/jWfFTa52  a list of over 600 NTLworld e-mail addresses with passwords.  My account is in that list, and the password listed is not only right, but it's unique to my virgin media account due to your poor security requirements (no special characters?? Must begin with a letter??  only 8-10 chars?) .   

So I can only conclude 'you' have had a breach?


I tried to change my contact e-mail address last night to a hotmail account and got an e-mail to tell me that had happened.  I also changed the password.

BUT since then the virgin website won't let me into account/profile areas (it crashes), and I still have to log in with the original e-mail address and old (compromised) password?!

I obviously want to change that password ASAP - could someone help me with that, and investigate why pages such as; https://my.virginmedia.com/my-profile/listUsers now crash?

"

Oops, something's broken

We're sorry this isn't the page you wanted.

This part of the site isn't working at the moment, but it'll be up and running again soon.

Other parts of the site might be working as normal, so try using the links below to help you find what you want."

cheers, Kristian

[Mod Edit – Removed Personal Information]

Java and Web developer at Frontline Ltd.
Created magsdirect.co.uk and many others.
0 Kudos
Reply
  • 18
  • 0
  • 1
krispy
Tuning in
305 Views
Message 2 of 14
Flag for a moderator

Re: NTLWorld e-mail account passwords on the net - account being abused

OK I've tried to change password again on the account - leaving the ntlworld e-mail as the login/username - and that seems to have worked this time.

So i'll leave the ntlworld e-mail as the login / contact for my account, and it's got a new password at least.  

But it still crashes when i try to get into https://my.virginmedia.com/my-profile/listUsers 


Java and Web developer at Frontline Ltd.
Created magsdirect.co.uk and many others.
0 Kudos
Reply
  • 1.09K
  • 50
  • 139
Forum Team
Forum Team
275 Views
Message 3 of 14
Flag for a moderator

Re: NTLWorld e-mail account passwords on the net - account being abused

Hello krispy

Thanks for your post 

Sorry to read hear about the issue you have had 

What I would like to do is get the page you are not able to view reported 

It will need me to pass security with your self via a private message 

Let me know if you are happy to proceed

Speak soon 

Gareth_L

0 Kudos
Reply
  • 18
  • 0
  • 1
krispy
Tuning in
271 Views
Message 4 of 14
Flag for a moderator

Re: NTLWorld e-mail account passwords on the net - account being abused

Hi Gareth - yes that would be great I'd like to get that page working again! 

Java and Web developer at Frontline Ltd.
Created magsdirect.co.uk and many others.
0 Kudos
Reply
  • 18
  • 0
  • 1
krispy
Tuning in
268 Views
Message 5 of 14
Flag for a moderator

Re: NTLWorld e-mail account passwords on the net - account being abused

the following URLS fail for me;

https://my.virginmedia.com/my-profile/
https://my.virginmedia.com/my-profile/view
https://my.virginmedia.com/my-profile/listUsers

but 
https://my.virginmedia.com/my-profile/my-preferences WORKS

Java and Web developer at Frontline Ltd.
Created magsdirect.co.uk and many others.
0 Kudos
Reply
  • 1.09K
  • 50
  • 139
Forum Team
Forum Team
259 Views
Message 6 of 14
Flag for a moderator

Re: NTLWorld e-mail account passwords on the net - account being abused

Cheers krispy

I Will drop you a Private message now 

Just check the purple envelope top right of your screen

Gareth_L

0 Kudos
Reply
  • 484
  • 37
  • 281
MissPasko
Fibre optic
253 Views
Message 7 of 14
Flag for a moderator

Re: NTLWorld e-mail account passwords on the net - account being abused

You have tried a different browser, right? And then clearing the history on your preferred browser.  That should be the first step to clear out bad cookies or whatever else makes pages fail.


~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

If you want to say thanks > click 'Kudos'.
Have we solved your issue? > click 'Mark as Helpful Answer'
0 Kudos
Reply
  • 18
  • 0
  • 1
krispy
Tuning in
249 Views
Message 8 of 14
Flag for a moderator

Re: NTLWorld e-mail account passwords on the net - account being abused

Yes and good point.  I tried in a different browser, then tried at work on a different PC.  Also in private browsing mode so previously cookies aren't available.

Java and Web developer at Frontline Ltd.
Created magsdirect.co.uk and many others.
  • 484
  • 37
  • 281
MissPasko
Fibre optic
247 Views
Message 9 of 14
Flag for a moderator

Re: NTLWorld e-mail account passwords on the net - account being abused


@krispy wrote:

Yes and good point.  I tried in a different browser, then tried at work on a different PC.  Also in private browsing mode so previously cookies aren't available.


Okay, I'm glad we've eliminated the simplest solution - back to the experts!  I hope they sort you out soon.


~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

If you want to say thanks > click 'Kudos'.
Have we solved your issue? > click 'Mark as Helpful Answer'
  • 1.09K
  • 50
  • 139
Forum Team
Forum Team
236 Views
Message 10 of 14
Flag for a moderator

Re: NTLWorld e-mail account passwords on the net - account being abused

Hi Krispy 

Thanks for passing security 

Just to let you know, I have raised the URL Issue with our IT department 

It can take a few days run an investigation and get a reply 

As soon as I have any updates, I will get back to you on here 

Gareth_L

0 Kudos
Reply