Live data from Hacker News

4M gmail addresses with passwords leaked (large html file, 150megs)

pred.me

21–30 of 31 posts

Re: 4M gmail addresses with passwords leaked (large html file, 150megs)

#22
post #2

Caution, this is a link to the actual emails.

Yeah not sure why one would link to that file directly.

I've changed the title to reflect the size but there is no story here without the link. What would you have done? I ask not to confront but rather to learn.

I didn't feel completely comfortable posting the link but thought it was better that it's out there (and it looks like it's not even new according to comments).

Re: 4M gmail addresses with passwords leaked (large html file, 150megs)

#23
I looked at the paste file. It had my gmail address (which is mostly what I use for public stuff) but the password came from only one place: travel.travelocity.com; however that user database is long gone as Travelocity is now just a brand of Expedia so that old account no longer exists. Of course I don't reuse passwords so it's not an issue. I wonder how it got there.

Re: 4M gmail addresses with passwords leaked (large html file, 150megs)

#25

Earlier quoted context omitted.

Yeah not sure why one would link to that file directly.

I've changed the title to reflect the size but there is no story here without the link. What would you have done? I ask not to confront but rather to learn. I didn't feel completely comfortable posting the link but thought it was better that it's out there (and it looks like it's not even new according to comments).

To download, I used:

  curl https://pred.me/gmail.html -vo /tmp/pred.me.gmail.$RANDOM.txt
There appear to be no malicous/unsafe at the moment. No HTML tags.

Just one email per line, and a colon (:) delimiter for the password.

The MD5 hash is:

  c1d5f3998459acea8d32937a4485c0b7
Availability is spotty. The server is refusing connections, probably due to high load.

The IP address resolved to:

  81.4.110.159
I don't think the direct link is out of line. Some users might need guidance on how to safely inspect the file.

In terms of HN community conventions and common behaviors, people will often submit a question like "Ask HN: Lorem Ipsum..." and then provide follow-up details in the message body, including relevant information, such as the details I've provided above.

This way, if the owner of the resource at the address starts serving up malware, users can verify the content before consuming it.

These are merely community memes though. Not any sort of auspicious, high-minded "best practices as prescribed by experts" or anything. Just some stuff a bro might do around here.

Also, WHOIS info might be useful, if safety or malware is a concern...

http://whois.domaintools.com/pred.me

This doesn't preclude the domain owner having been pwnt and used as a patsy. Or even whether that person might have a valid reason for hosting the file?

Post reply on HN