ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Mirosoft patches Hotmail security flaw

Lisa M Bowman ZDNet.co.uk

Published: 31 Aug 1999 08:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The private accounts of millions of Hotmail users were left exposed for hours, after several Web sites exploited a security hole in Microsoft software. (See full story.)

The Web sites let anyone read, send or delete mail from an account simply by typing in a user name. No password was required. Microsoft took its Hotmail servers down Monday morning after learning of the problem from the European press (several of the sites originated in Europe). By late morning, Microsoft said it had plugged the hole and promised that future attacks would be prevented.

Some readers sent messages to ZDNet Monday afternoon saying they could still raid people's accounts, but security experts said that's because Microsoft is going from server to server, fixing the problem. With 40 to 50 million users, Hotmail is the largest email service.

The hack apparently exploited a glitch that let Hotmail accept users as valid without cross-checking the URL that referred them to the site. A Microsoft spokeswoman said she didn't think people really cared how the security hole was exploited, only that the hole had been fixed to prevent future breaches. She said the hack required a "very advanced knowledge of Web development language".

However, several computer experts said the code that took advantage of the Hotmail hole -- code that's been posted on hacker sites -- was actually quite simple. "It's trivial. It's just some HTML code," said Richard Smith, security expert and president of Phar Lap software, who was instrumental in catching the creator of the Melissa virus.

Jay Dyson, a computer systems specialist in Pasadena, called the code "pathetically easy" to write. What's more, exploiting the hack to view someone's account doesn't require any computer proficiency -- only a browser and the ability to type in a user name. "The script is so trivial, I would be inclined to believe that this has been in the wild for a long time," Dyson said.

Code is considered "in the wild" when it's passed among hackers without actually being exploited by users. But apparently some found this code too compelling to resist, so they posted sites that let users spy on other people's accounts.

One of the earliest sites to exploit the bug was registered to Stockholm, Sweden-based Moving Pictures. In an email exchange with ZDNet News, Erik Barkel, the person listed on Network Solutions as the administrator said: "I got credit for something I didn't do. I didn't code. I did put up a mirror." After the Hotmail hack site was taken down, the URL registered to Moving Pictures was directing people to a variety of sites, including Microsoft's own security page and a rant about Internet standards and date-related software problems.

Microsoft said it had no immediate plans to notify users that their Hotmail accounts may have been read. Callers to Hotmail's technical support line were greeted with waits as long as 20 minutes. Technical support people were telling users that discarded Hotmail messages would still be in the trash, and documents that had been read would be marked as such.

Computer consultants and security experts hoped the move would be a wake-up call for consumers to demand more secure software. "Basically the consumers are going to have to start asking for better security or Microsoft's not going to see it as a big problem," B.K. DeLong, a computer consultant, said. He said until users do that, Microsoft isn't going to make security a priority.

"It's just another example of large software companies doing reactive bug fixing rather than proactive bug fixing," he said. "It's very frightening."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
85 out of 129 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Test Analyst required - Central London

The successful candidate will have experience of functional & web testing of large complex environments with strong problem solving & bug fixing ...

Flash Developer - AS2.0 - Digital

The project will involve you making feature ammendments and bug fixing to the code base of their video player whilst they roll out a new portfolio of ...

Web Developer Contract Aylesbury Immediate start

We require: XML, XSLT, XHTML, CSS, knowledge of Java, experience in systems administration, unit testing & bug fixing This will be to complete the ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments