ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

A Year Ago: Hotmail glitch steals passwords

Matthew Broersma ZDNet.co.uk

Published: 25 Aug 1999 07:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Canadian Web programmers have uncovered a security glitch that could fool users of Microsoft's Hotmail e-mail service into revealing their passwords.

The glitch allows a malicious user to send a malicious Java applet to a Hotmail user. The applet, which runs as soon as the e-mail message is viewed, alters the Web-based user interface of the Hotmail account, creating a false timeout message, and asking the user to re-enter his or her password in order to use the account.

Once Hotmail users re-enter their password, they return to the normal Hotmail interface -- but the password is mailed to the malicious user. Canadian Specialty Installations -- a reseller -- posted a demonstration of the exploit, which it calls "Hot" Mail, on the Web site "Because-we-can," which publishes the work of Specialty Installations Web programmers. "The security problem is easy to take advantage of," said the programmers in a message posted on because-we-can.com. "A would-be hacker needs only to embed the JavaScript code into the body of an e-mail message using a standard e-mail program such as Netscape Mail."

Hotmail officials did not immediately return telephone calls.

Once a user has someone's password, he or she can not only alter that Hotmail account, but can also alter or delete messages on an Internet service provider e-mail account, through the POP-mail feature on Hotmail.

The glitch works on any Java-enabled browser, according to Specialty Installations. The programmers recommend users turn off JavaScript on their browsers while using Hotmail, until the problem is fixed.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
38 out of 104 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:


















Related Jobs

Front end specialist PHP Developer, Birmingham, 25k

Experience required: Strong HTML Strong CSS Strong Ajax Expert knowledge of W3C web standards Good JavaScript Good PHP5 Preferred: SQL ...

Account Executive Healthcare PR, London - 22-26k

Leading healthcare PR agency seeks Account Executive This is a rare opportunity for an ambitious individual to join one of the UKs leading healthcare ...

Seeking Available JavaScript / EXT JS Developers!

There is currently a great demand for experienced programmers who are highly skilled with JavaScript; in particular EXT. These programmers are needed ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment