Advertisement
Promo

Security threats Toolkit

A Year Ago: Hotmail glitch steals passwords

Matthew Broersma ZDNet.co.uk

Published: 25 Aug 1999 07:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Canadian Web programmers have uncovered a security glitch that could fool users of Microsoft's Hotmail e-mail service into revealing their passwords.

The glitch allows a malicious user to send a malicious Java applet to a Hotmail user. The applet, which runs as soon as the e-mail message is viewed, alters the Web-based user interface of the Hotmail account, creating a false timeout message, and asking the user to re-enter his or her password in order to use the account.

Once Hotmail users re-enter their password, they return to the normal Hotmail interface -- but the password is mailed to the malicious user. Canadian Specialty Installations -- a reseller -- posted a demonstration of the exploit, which it calls "Hot" Mail, on the Web site "Because-we-can," which publishes the work of Specialty Installations Web programmers. "The security problem is easy to take advantage of," said the programmers in a message posted on because-we-can.com. "A would-be hacker needs only to embed the JavaScript code into the body of an e-mail message using a standard e-mail program such as Netscape Mail."

Hotmail officials did not immediately return telephone calls.

Once a user has someone's password, he or she can not only alter that Hotmail account, but can also alter or delete messages on an Internet service provider e-mail account, through the POP-mail feature on Hotmail.

The glitch works on any Java-enabled browser, according to Specialty Installations. The programmers recommend users turn off JavaScript on their browsers while using Hotmail, until the problem is fixed.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
39 out of 110 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:


















Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters