<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thunderbird email hack using Sabre/Dav in Discussions</title>
    <link>https://connect.mozilla.org/t5/discussions/thunderbird-email-hack-using-sabre-dav/m-p/27361#M10828</link>
    <description>&lt;P&gt;I am using the Thunderbird mail program for some time and overall have been happy until tonight. I am not a programmer, but do have a good understanding of what is happening on my system.&amp;nbsp; I have built my own computers for a very long time, have my own server, and other things... playing with computers for probably the past 50+ years. I owned the HP-35 of about 1973, recall the SCAMP and the Altair systems.&lt;/P&gt;&lt;P&gt;Anyway, some hacker is using a Sabre/DAV program to modify the Thunderbird mail program as I found out tonight with a threat and extortion attempt, wanting me to pay via bitcoin.&amp;nbsp; This Sabre/Dav program that I am not familiar with is some kind of PHP program. This hacker was able to install his address:&amp;nbsp; https:// (youremail). com or what ever you use, using port 8443 (SabreDav).&amp;nbsp; What ever mail activity being used is sent thru&amp;nbsp; this port to him.&amp;nbsp; All mails and what you are doing.&lt;/P&gt;&lt;P&gt;It is installed on Thunderbird under: Account Settings for the specific mail program&amp;gt; Thunderbird Settings&amp;gt;Privacy and Security&amp;gt;Passwords&amp;gt;Saved Passwords.&lt;/P&gt;&lt;P&gt;When you access this area you will see where&amp;nbsp; the hack was installed. For example, it might look like: &lt;A href="https://johndoe.de:8443(SabreDAV)" target="_blank"&gt;https://johndoe.de:8443(SabreDAV)&lt;/A&gt;.&amp;nbsp;&amp;nbsp; It is not any imap or smtp, or mail account.&amp;nbsp; I am sure there are some other mods but I have not found anymore so far.&amp;nbsp; I have deleted this "add-on" account, and also disabled the listening port he/she was using, both in-bound and out-bound.&lt;/P&gt;&lt;P&gt;I have notified friends and family of the hack and the threats and extortion attempt.&amp;nbsp; Personally so long as my external accounts are protected, i do not give a moose .... I am nearly 70 years old and at this age I do not think he can hurt me very much.&amp;nbsp; I have been changing my email accounts and passwords to be safe.&amp;nbsp; He also claims to have access to my web cam, my chats, messenger, microphone, etc...&amp;nbsp; The funny thing is I have NO social media, I have NO cam on my computer, I have NO microphone on my system, No messenger, etc....&amp;nbsp; for the simple reason is due to people like this, and I like my privacy.&amp;nbsp; Google, Ymail, and the rest are a privacy risks... so you can see he is bluffing at this part.&amp;nbsp; I will not know the extent of the damage until later on since I have refused to pay him via bitcoin.&lt;/P&gt;&lt;P&gt;I am hoping some programmer at Thunderbird can figure out how he/she did this and fix it; prevent this from happening to others.... and I would appreciate some feedback on what I may have&amp;nbsp; missed, and how he/she did this.&amp;nbsp; I have an alternate account and you can reach me at: nh19926@gmail.com&lt;/P&gt;&lt;P&gt;Norm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Mar 2023 06:06:49 GMT</pubDate>
    <dc:creator>nh19926</dc:creator>
    <dc:date>2023-03-20T06:06:49Z</dc:date>
    <item>
      <title>Thunderbird email hack using Sabre/Dav</title>
      <link>https://connect.mozilla.org/t5/discussions/thunderbird-email-hack-using-sabre-dav/m-p/27361#M10828</link>
      <description>&lt;P&gt;I am using the Thunderbird mail program for some time and overall have been happy until tonight. I am not a programmer, but do have a good understanding of what is happening on my system.&amp;nbsp; I have built my own computers for a very long time, have my own server, and other things... playing with computers for probably the past 50+ years. I owned the HP-35 of about 1973, recall the SCAMP and the Altair systems.&lt;/P&gt;&lt;P&gt;Anyway, some hacker is using a Sabre/DAV program to modify the Thunderbird mail program as I found out tonight with a threat and extortion attempt, wanting me to pay via bitcoin.&amp;nbsp; This Sabre/Dav program that I am not familiar with is some kind of PHP program. This hacker was able to install his address:&amp;nbsp; https:// (youremail). com or what ever you use, using port 8443 (SabreDav).&amp;nbsp; What ever mail activity being used is sent thru&amp;nbsp; this port to him.&amp;nbsp; All mails and what you are doing.&lt;/P&gt;&lt;P&gt;It is installed on Thunderbird under: Account Settings for the specific mail program&amp;gt; Thunderbird Settings&amp;gt;Privacy and Security&amp;gt;Passwords&amp;gt;Saved Passwords.&lt;/P&gt;&lt;P&gt;When you access this area you will see where&amp;nbsp; the hack was installed. For example, it might look like: &lt;A href="https://johndoe.de:8443(SabreDAV)" target="_blank"&gt;https://johndoe.de:8443(SabreDAV)&lt;/A&gt;.&amp;nbsp;&amp;nbsp; It is not any imap or smtp, or mail account.&amp;nbsp; I am sure there are some other mods but I have not found anymore so far.&amp;nbsp; I have deleted this "add-on" account, and also disabled the listening port he/she was using, both in-bound and out-bound.&lt;/P&gt;&lt;P&gt;I have notified friends and family of the hack and the threats and extortion attempt.&amp;nbsp; Personally so long as my external accounts are protected, i do not give a moose .... I am nearly 70 years old and at this age I do not think he can hurt me very much.&amp;nbsp; I have been changing my email accounts and passwords to be safe.&amp;nbsp; He also claims to have access to my web cam, my chats, messenger, microphone, etc...&amp;nbsp; The funny thing is I have NO social media, I have NO cam on my computer, I have NO microphone on my system, No messenger, etc....&amp;nbsp; for the simple reason is due to people like this, and I like my privacy.&amp;nbsp; Google, Ymail, and the rest are a privacy risks... so you can see he is bluffing at this part.&amp;nbsp; I will not know the extent of the damage until later on since I have refused to pay him via bitcoin.&lt;/P&gt;&lt;P&gt;I am hoping some programmer at Thunderbird can figure out how he/she did this and fix it; prevent this from happening to others.... and I would appreciate some feedback on what I may have&amp;nbsp; missed, and how he/she did this.&amp;nbsp; I have an alternate account and you can reach me at: nh19926@gmail.com&lt;/P&gt;&lt;P&gt;Norm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 06:06:49 GMT</pubDate>
      <guid>https://connect.mozilla.org/t5/discussions/thunderbird-email-hack-using-sabre-dav/m-p/27361#M10828</guid>
      <dc:creator>nh19926</dc:creator>
      <dc:date>2023-03-20T06:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: Thunderbird email hack using Sabre/Dav</title>
      <link>https://connect.mozilla.org/t5/discussions/thunderbird-email-hack-using-sabre-dav/m-p/27570#M10871</link>
      <description>&lt;P&gt;Apparently port 8443 is used for Calendar and this is how he gained access to Thunderbird and my email accounts.&amp;nbsp; I do not use this Calendar program.&amp;nbsp; I am still hoping the Thunderbird Staff can fix this hole in the program.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 04:31:21 GMT</pubDate>
      <guid>https://connect.mozilla.org/t5/discussions/thunderbird-email-hack-using-sabre-dav/m-p/27570#M10871</guid>
      <dc:creator>nh19926</dc:creator>
      <dc:date>2023-03-22T04:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Thunderbird email hack using Sabre/Dav</title>
      <link>https://connect.mozilla.org/t5/discussions/thunderbird-email-hack-using-sabre-dav/m-p/31396#M11798</link>
      <description>&lt;P&gt;I know it's probably a bit late now, but do you have any screenshots of the threats requesting bitcoin and of the website?&lt;/P&gt;&lt;P&gt;I looked up sabre/dav and it seems to be a server for CalDAV which is what you use for syncing calendars and contacts, but it could possible that someone modified it to be malicious, or just using it as a backend to send your emails to.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't work for Thunderbird, I'm just curious about this.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 20:55:08 GMT</pubDate>
      <guid>https://connect.mozilla.org/t5/discussions/thunderbird-email-hack-using-sabre-dav/m-p/31396#M11798</guid>
      <dc:creator>nose_gnome</dc:creator>
      <dc:date>2023-05-10T20:55:08Z</dc:date>
    </item>
  </channel>
</rss>

