Just deleted my last pass account!
here's the info that came with the email
Time Monday, December 27, 2021 at 1:41 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.88.235
Just deleted my last pass account!
here's the info that came with the email
Time Monday, December 27, 2021 at 1:41 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.88.235
Also, incorrect login attempts (i.e. using the wrong password) does not send out an email.
If you do attempt to login with the correct master password from a different/new IP, then you'll get the "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" email.
It's not the most scientifically accurate method, but a few people and I are trying to rule out / determine which software in common all of us might have. Thanks!
We need to find a common thread.
How is this possible????
What is the probability that you, techknight (the other user in this thread) and me used the exact same compromised software back in ~2017 and had our master passwords stolen then? And for that person/bot (in Brazil) to try all of those master passwords now?
It's beginning to look like this is a LastPass issue, no..?
I've emailed you a list of the extensions I use in Chrome - if you want to share publicly any that we have in common I'm okay with that
Since I haven't used this LastPass master password since 2017, I'd have to remember which extensions I had back then, which is hard to do...
I may have had 1Password and Adblock Plus which you had/have too.
But it's hard to say. It's a possible vector (that you, dogman123 and I had the same compromised extensions) but also... why would the hackers have sat on our master passwords for nearly 4 years (in my case)?
It's looking like you got phished a long time ago, or installed malware which targeted the lastpass extension.
Did all of you use the same OS four years ago? (Windows perhaps?) Some malware targets Chrome/Firefox files on disk. A malicious extension probably wouldn't be able to affect your LastPass extension, but a malicious malware app could easily modify it.
I used macOS/Chrome back in 2017. I definitely could have been phished then, or used a compromised extension.
Or does LP shoot an email if it detects a suspicious geo-IP login before the 2FA prompt?
Once the IP is approved (you have to follow a link from the email), then you login again with the correct password and then get the 2FA prompt.
Edit: I found an old post from about 5 years ago on a vulnerability in LastPass’s extension [0]
pw was only ever used here and stored offline
Or I am drawing a random line through a cloud of dots..? :-)
What other IPs are part of BLAZING_SEO_PROXY?
It's not the most scientifically accurate method, but a few people and I are trying to rule out / determine which software in common all of us might have. Thanks!
If you try hitting it, it will redirect you to some website which might or might not be the same to every person
It's not the most scientifically accurate method, but a few people and I are trying to rule out / determine which software in common all of us might have. Thanks!
Logging in with the wrong password is logged in the Account History as "Failed Login Attempt"
Logging in with the correct password (or hash? TBD) from a new IP triggers the email and that's logged in the Account History as "Login Verification Email Sent"