Hacker News new | ask | show | jobs
by tonymon 4295 days ago
Links to zip archive with plain email list (without passwords):

https://mega.co.nz/#!ewU1wCKA!P52rdL5tMcugRxi8ALyZlGnfE_KSB4...

Alternative: http://rghost.net/57937836

The thing is that this site mentions other site where in comments section you can find links to 7zip archive with emails

4 comments

Interestingly, there are a large number of non-gmail.com addresses in there, including 123k yandex.ru addresses, plus a (very) small number of yahoo.com and hotmail.com addresses. Here's the output of "cut -d@ -f2 | sort | uniq -c | sort -nr":

https://gist.github.com/anonymous/255959493c0a26cce856

The data hasn't been very well edited from whatever dump it came from. For example, there are lines that end in "gmail.com_xtube", "gmail.com7777", "gmail.com|login", etc, which are curious.

OK, my address was in there. I've changed my password. But, how do I know if they actually had my correct password? Shit this is scary...
Assuming hacker did sign in into your Gmail , you might be able to get that information from the list of last logins in your Gmail account. Any IP that's out of your normal location would reveal that. More in this link https://support.google.com/mail/answer/45938?hl=en
Yeah, this is an account that only forwards emails, so I almost never log in. However, when I changed my password now I logged in and out a bunch of times. This made this very short list of recently logged locations only contain one line that was not from today. Hmm. Would be better if they showed 50 recent logins or something...
The webpage will give you the first two letters of your password.
The webpage gave the correct first two letters of my password...but that was changed more than a year and half ago, so this leak must be VERY old. I have been using last pass for the past time and when I got it I immediately changed my google password. This is the reason why I'm saying is that old.
I bet there are some people who have other leaked account & password lists, and since the isleaked.com site is kind enough to give the first two characters of the password for any given email account, it'd probably be possible to guess the passwords for some of those accounts.
Am I blind? I only see if there is a match, no password initial letters at all ???

EDIT: Not blind, it just doesn't show the initial letters if you search using a wildcard even if there is only 1 match.

Thanks! Checking that list against my gmail contacts, I found six of my friends in there!
Did the same, found one.