- More porn sneaks onto the iPhone
- 'Swatting' case shows need to ban caller-ID spoofing
- Why the iPhone can't be "killed"
- Nortel enterprise chief wants to bring back Bay
- US sets final emergency responder wireless pilot
Your Web mail account is a treasure trove of private and potentially valuable information -- and thieves know it. In an online interview, one phisher claimed to make thousands of dollars every day by breaking into people's E-mail accounts and searching for messages that contain financial details.
Normally you can't tell whether you've been hacked in this way. Even if you cannily leave a juicy-sounding e-mail unread, a thief or snoop may read it and then return its status to unread. But with a little bit of know-how, you can create an electronic trip wire that will trigger whenever someone reads a rigged e-mail.
I came across the idea, which takes advantage of a free Web hit counter, in a blog post by Jeremiah Grossman of WhiteHat Security. After I talked with him, we came up with a setup that's easier than the one he originally suggested.
The gist of it is to keep an e-mail message in your account that includes the code for the counter. Opening the attachment trips the counter, thereby alerting you that someone was snooping.
Here's how to set it up:
1. Head over to OneStatFree.com and register for a free Web counter account. You can list anything for the site URL, and use a disposable e-mail address to complete the registration process (click for tips on using such e-mail accounts).
2. Look for an e-mail from OneStat sent to the address you used when you registered. It will come with an attached file named OneStatScript.txt. Save that file, and note your account number. Then delete the e-mail, which has your account details.
3. Give the .txt file a name that will catch a spy's eye, like "BankPasswords," and make it an .htm file so it opens automatically in a Web browser (and trips the counter).
4. Send the file as an e-mail attachment to the Web mail account that you want to monitor. Use a similarly baited subject line, like "Account log-ins," for the message. Just be sure not to open the file when you send it -- you don't want to set off your own alarm.
5. Sit back and wait like the patient spy-catcher you are. If anyone opens your rigged attachment, the hit counter will reflect that fact and will record information about them, including the IP address of the accessing computer. To check the counter stats, just log back in to your account at OneStatFree.com.
Comments (4)
xnetstat5By Anonymous on November 29, 2008, 6:04 am xnetstat5
Reply | Read entire comment
web bug? that's NOT original & NOT effectiveBy erik is a tard on February 20, 2008, 1:44 amToo bad the DEFAULT for ALL clients and webmail alike is to NOT SHOW IMAGES. email security = encryption Don't want someone reading your email? Use a secure...
Reply | Read entire comment
Are you sure this is legal?By Anonymous on July 30, 2007, 4:35 pmIn the instructions, you say to sign up at Onestat.com with ANY URL, but the signup page at onestat.com (http://www.onestat.com/aspx/signup.aspx?v=1&lang=en&osadcampaign=onestatfree)...
Reply | Read entire comment
RE: Set a hacker alarm on your Web mail boxBy didi on July 28, 2007, 3:03 pmmaaf mas di protect yo.....?
Reply | Read entire comment
View all comments