Hack/Blackmail email due to vulnerability sql-inj on the imap.plus.net system
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- :
- Hack/Blackmail email due to vulnerability sql-inj ...
Hack/Blackmail email due to vulnerability sql-inj on the imap.plus.net system
21-08-2021 5:02 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I have just received an email (sent from my email account) quoting my email account and password and demanding a sum of money to stop disseminating my contacts, emails etc. The worrying thing is that it came from my email and quoted the correct password.
Has anyone come across this SQL-INJ vulnerability and is there a work around?
Re: Hack/Blackmail email due to vulnerability sql-inj on the imap.plus.net system
21-08-2021 5:39 PM - edited 21-08-2021 5:40 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
and tell them to Foxtrot Oscar .......
Re: Hack/Blackmail email due to vulnerability sql-inj on the imap.plus.net system
22-08-2021 8:50 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
It my appear to come from your own account but if you check it the email should be in your own sent folder, is this the case?
How do you know this is a SQL Injection attack and not caused by a lack of security elsewhere?
Re: Hack/Blackmail email due to vulnerability sql-inj on the imap.plus.net system
22-08-2021 10:18 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Change password immediately and on any other account that use the same password also use, https://haveibeenpwned.com/ too see if its been exposed else ware
Re: Hack/Blackmail email due to vulnerability sql-inj on the imap.plus.net system
22-08-2021 11:49 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
The email sender was my address but I've checked my Sent emails and it is not there. Re "how do I know it is an SQL-INJ". Only from what the email said "I want to inform you, using a discovered vulnerability sql-inj on the imap.plus.net control of the site was seized by me ".
I've changed my password for the account.
Re: Hack/Blackmail email due to vulnerability sql-inj on the imap.plus.net system
22-08-2021 2:44 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@britbolton As it wasn't in your Sent folder then I doubt it was sent from your account. The references to SQL Injection were, I suspect, there to convince you of the legitimacy of the possibility should you search the subject. By far the best proof your account's been compromised would be to send it direct from your account and leave it in the Sent folder.

Re: Hack/Blackmail email due to vulnerability sql-inj on the imap.plus.net system
22-08-2021 3:10 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@britbolton wrote:
I've changed my password for the account.
Does your email account provider have/use two factor authentication if it has I would set it up.
If not I would change to an email provider who uses two factor authentication as an extra layer of security a pain some times but well worth using.
HD
Re: Hack/Blackmail email due to vulnerability sql-inj on the imap.plus.net system
22-08-2021 5:08 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
My email provided is Plusnet. I can't find any info as to whether Plusnet provides TFA. Do you know?
Re: Hack/Blackmail email due to vulnerability sql-inj on the imap.plus.net system
22-08-2021 5:14 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@britbolton I don't think they do - but I could be wrong.

Re: Hack/Blackmail email due to vulnerability sql-inj on the imap.plus.net system
22-08-2021 5:37 PM - edited 22-08-2021 5:40 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I think John is right and the storage is very low
GMail has 15GB of storage and TFA and if you change provider you don't have to mess about with the email address
I know they look at your account but I do nothing I shouldn't
HD
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- :
- Hack/Blackmail email due to vulnerability sql-inj ...