sammyjenkis
Hall of Fame
Per Brohio, Weiss was able to defeat the poor security on the athletic system password database. From another comment of his on March 27th:I don't think he would have gotten the passwords from the athletic training site....but like I said, crackers are easy to obtain and are usually very fast for most passwords. and since humans are creatures of habit and reuse things, you nailed it - easily repeatable/easily breakable.
Second thing I want to address is the Weiss situation. I’ve noticed a sentiment of “how could a dumb jock football coach pull off something this complex?” I think that stems from misconceptions people have about hacking they’ve learned from the movies. Hacking isn’t furiously typing on a keyboard while binary code flies across the screen like in the Matrix. It’s heavily reliant on social engineering typically and in this case, Weiss essentially had a cheat sheet in the form of a large database containing email addresses and passwords which he would attempt to use across platforms in hopes women used the same passwords for their other personal accounts. The indictment mentioned he was researching pet names, maiden names etc. This is pretty telling of his methodology. These details are the most common answers to security questions that generate when you submit a password reset request. So he was likely breaking in to accounts he couldn’t access with a password directly (but had access to the email associated with the account) by submitting a password reset. The point I’m trying to make is that this is all very simple stuff.
Upvote
0