Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


NZGamingIcon

66 posts

Master Geek


#223302 22-Sep-2017 22:17
Send private message

Hello peeps

Anyone here have 2degrees webmail? preferably using a snap domain.

 

Need to confirm if there is a security hole.

1) Change the password to your email address to more than 8 characters long, password can be anything e.g. qwerty12345
2) Attempt to login to your email with only the first 8 characters e.g. qwerty12
3) Report results on this thread.

My email was hacked and was being used to send out spam, then figured out that only the first 8 characters were being used which would of made it much easier for someone to hack.

Issue was logged with 2degrees and it's been sitting with them for close to 3 weeks with no updates. Every time I call them they give me the same bs. They also said I'm the only person impacted by this password issue which I find hard to believe. Most likely they messed up >=8 char security rule and have it logged with their development team to fix which is why it's taking so long to get an answer.

If it is widespread 2degrees would need to notify their customers that their webmail service has a security hole.



Create new topic
kingjj
1728 posts

Uber Geek

ID Verified
Trusted

  #1871310 23-Sep-2017 08:19
Send private message

Just tried it with a fresh @snap.net.nz address and it did not work. Worked with full password but not first 8 only.




Andib
1364 posts

Uber Geek

ID Verified
Trusted

  #1871388 23-Sep-2017 10:57
Send private message

I haven't reset my password but my password is longer than 8 characters.

 

Can confirm I could logon by just using the first 8 characters.

 

Edit: Just confirmed I can put anything after the 8th character and it accepts it. (ie Passwordxyz works when the password is "Password1")





<# 
       .DISCLAIMER
       Anything I post is my own and not the views of my past/present/future employer.
#>


Lias
5590 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1871427 23-Sep-2017 12:20
Send private message

PM'd someone I know at 2Degrees and pointed them at this thread. May help speed things up.





I'm a geek, a gamer, a dad, a Quic user, and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it. If you use my Quic signup you can also use the code R570394EKGIZ8 for free setup.




2degreesCare
1537 posts

Uber Geek

Trusted
2degrees

  #1871430 23-Sep-2017 12:29
Send private message

Hey all,

 

We are not aware of any widespread issue with our webmail service at this time.

 

Can those that are affected please message us here privately with the email address in question, along with your broadband customer number and physical address, and we'll be more than happy to look in to this here for you and see what the story is.

 

Thanks,

 

Ralph ^JOB


Andib
1364 posts

Uber Geek

ID Verified
Trusted

  #1871462 23-Sep-2017 13:35
Send private message

Note a 2D customer anymore but still have my Snap email. Have PM'd you





<# 
       .DISCLAIMER
       Anything I post is my own and not the views of my past/present/future employer.
#>


hio77
12999 posts

Uber Geek

ID Verified
Trusted
Lizard Networks

  #1871662 23-Sep-2017 19:54
Send private message

This reminds me of bank logins.

 

 





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have.

 

 


NZGamingIcon

66 posts

Master Geek


  #1895342 4-Nov-2017 21:15
Send private message

 Still haven't heard anything.


 
 
 

Trade NZ and US shares and funds with Sharesies (affiliate link).
SATTV
1649 posts

Uber Geek

ID Verified

  #1895343 4-Nov-2017 21:35
Send private message

Just seen the thread and confirm that this is an issue for me.

 

My password was over 8 characters to start with.

 

John





I know enough to be dangerous


xpd

xpd
Geek @ Coastguard NZ
13771 posts

Uber Geek

Retired Mod
ID Verified
Trusted
Lifetime subscriber

  #1895469 5-Nov-2017 13:17
Send private message

Heh... reminds me back in the IHUG days where I found long as you knew someones IHUG username, you could log into their homepage space usage checker with any password - so you could see any "hidden" dirs/files the user had on their site. Told webmaster, they fixed it, then following week restored from an old backup and put the problem straight back. 





       Gavin / xpd / FastRaccoon / Geek of Coastguard New Zealand

 

                      LinkTree

 

 

 


NZGamingIcon

66 posts

Master Geek


  #1948787 30-Jan-2018 18:38
Send private message

Many months later, issue still not fixed.

I'm assuming the issue was over their head and they gave up on attempting to fix it. They probably raised a p4 ticket on the day, then once they realised they couldn't fix it decided to resolve + close the ticket with no customer visibility. No ticket ownership, no checking with user, no nothing. 

Decided to give 2degrees a call, got the response "our technical team is still looking into it, and we are waiting for an update from them".

How many months does it take to get an update? You would think an issue like this that is widespread impacting mail security would be considered important. 

 

 


Yabanize
2350 posts

Uber Geek


  #1948814 30-Jan-2018 18:46
Send private message

Scary, that means they're not hashing passwords?


freitasm
BDFL - Memuneh
79316 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1948837 30-Jan-2018 19:49
Send private message

Yabanize:

 

Scary, that means they're not hashing passwords?

 

 

Not necessarily. Perhaps they truncate the password, hash it then store in the database. Still would pass as per OP's description.





Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 


NZGamingIcon

66 posts

Master Geek


  #1949585 31-Jan-2018 19:06
Send private message

freitasm:

 

Yabanize:

 

Scary, that means they're not hashing passwords?

 

 

Not necessarily. Perhaps they truncate the password, hash it then store in the database. Still would pass as per OP's description.

 




Interesting, I don't think they are hashing passwords, because the CSR's have visibility to the password which is very scary indeed. Perhaps their database was already hacked, would explain how my webmail account was compromised and used as a mail bot last year. 

I spoke to one of the CSR's today who seemed more helpful than previous experiences. What we found was that when he changes my password on his end, I can no longer login using only the first 8 characters, and can only login when all characters are matching. However, when I change the password myself through their web portal (https://secure.2degreesbroadband.co.nz/email) it accepts the password as long as the first 8 characters are correct.

 

Perhaps the front-end is truncating the password to first 8 chars before storing to the database? but even that wouldn't make sense, as I can login using any password as long as the first 8 chars are matching. e.g. set password to 'password12345' would be able to login with 'password999' or 'passwordaaaaaa' etc..


UHD

UHD
655 posts

Ultimate Geek
Inactive user


  #1949654 31-Jan-2018 19:50
Send private message

I suppose the developers are enjoying a nice long holiday?

2degreesCare
1537 posts

Uber Geek

Trusted
2degrees

  #1950548 2-Feb-2018 09:50
Send private message

Hi @NZGamingIcon,

 

Our technical team have been working on this issue since this was raised in September - thank you again for bringing it to our attention. The issue is the method of encryption we previously used to store these passwords which truncated to 8 characters only.

 

We are now halfway there to resolving the issue, and password changes done by our Customer Care team will use a new encryption method not vulnerable to this issue, however changes online will still use the old method.

 

We're also upgrading all existing passwords to the newer encryption method retroactively, so if your password stops working you may be using/autofilling the truncated version. Just give our team a call on 0800 022 022 opt 9 to get that sorted.

Cheers, ^BRM


Create new topic





News and reviews »

Gen Threat Report Reveals Rise in Crypto, Sextortion and Tech Support Scams
Posted 7-Aug-2025 13:09


Logitech G and McLaren Racing Sign New, Expanded Multi-Year Partnership
Posted 7-Aug-2025 13:00


A Third of New Zealanders Fall for Online Scams Says Trend Micro
Posted 7-Aug-2025 12:43


OPPO Releases Its Most Stylish and Compact Smartwatch Yet, the Watch X2 Mini.
Posted 7-Aug-2025 12:37


Epson Launches New High-End EH-LS9000B Home Theatre Laser Projector
Posted 7-Aug-2025 12:34


Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.