Advertisement
Promo

Online business Toolkit

Hotmail vulnerability exposed

Eric J. Bowden, BugNet ZDNet.co.uk

Published: 04 Sep 2000 09:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Haven't upgraded Internet Explorer yet? Maybe this will convince you. ZDNet's sister site BugNet has validated a security vulnerability that could allow a malicious user to gain access to your Hotmail account.

By enticing a Hotmail customer running Internet Explorer 4.x or 5.0 into clicking on a carefully constructed link, the unwary victim would be tricked into abdicating crucial cookie information that would allow the hacker to gain access to the Hotmail account. This is not a new bug, but a new exploit of an old bug originally reported on 17 May.

Even though newer versions of Internet Explorer are readily available, there are still a lot of people using the version that came with Windows 98. For some, they don't want to touch something that seems to be working fine. For others, the sheer size of the download makes the prospect of upgrading over a dial-up connection seem like an insurmountable task. This latest security alert should serve as a wake up call that maybe it is time to bite the bullet and upgrade.

We used KeyLabs to verify this vulnerability on systems running Internet Explorer versions 4.x and 5.0. KeyLabs was also able to verify that versions 5.1 and 5.5 are immune.

This bug was originally reported to BugNet by an Internet developer from Denizli, Turkey. Alp Sinan, owner of Pronet, a security consulting company, was able to apply the "Unauthorised Cookie Access" vulnerability in a new way to create this exploit. Using his sample code, we were able gain access to our test Hotmail accounts and not only read but also write emails on the unauthorised account.

The core of the problem within Hotmail is that the security is built on cookies (mostly session cookies). Hotmail's current authentication works as follows: Hotmail sends the user an encoded cookie when the user's sign-in name and password are entered. The user's browser then uses the information in the cookie to authenticate with the Hotmail server throughout the life of the Hotmail session. If the user can be tricked into sending this session cookie to a hacker, then the hacker can also gain access to the victim's account.

While it is true that Microsoft has eliminated the "Unauthorised Cookie Access" problem with its latest releases of Internet Explorer, our concern is that we don't know what new browser bugs are going to emerge tomorrow. Therefore, a Web site like Hotmail has a fiduciary responsibility to protect user information.

Somethings we might suggest to Hotmail is that when the Web site sets an authentication cookie, it needs to include variables representing important information like the user's session IP address or the computer name. This would prevent the cookie information from being used on another system. In the meantime, it's time to upgrade your browser.

Netscape is likely to suffer from the same Hotmail vulnerability. Currently, the only way to protect your Hotmail account is to upgrade Internet Explorer with either the Internet Explorer 5.01 Service Pack 1 or by downloading Internet Explorer 5.5. You can also upgrade your older version of Netscape with its latest, Netscape 4.75.

Take me to Hackers

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
32 out of 74 people found this useful


Full Talkback thread

1 comment

  1. Can you tll me how I get connected to the internet... nick goddard

Company/Topic Alerts

Create a new alert from the list below:











Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters