ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Hotmail 'glitch' an inside job?

Will Knight ZDNet.co.uk

Published: 31 Aug 1999 13:19 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A British hacker-turned-security consultant, who requested anonymity, told ZDNet UK News this morning that the nature of the script -- that is, the accuracy of its parameters -- may indicate that an insider, or at least someone with an intimate knowledge of Hotmail's internal workings, is be at the centre of the controversy.

According to the source, to have created the admin script responsible for the exploit would require knowledge of key parameters difficult to guess but common knowledge among Hotmail administrators. "The Swedish hacking group that have claimed responsibility for this crack may not even exist," says the source. "It would be very difficult to guess these parameters. The use of these would seem to indicate that someone must have had inside contact at some point."

The only alternative, the source believes, is that the exploit is based on the workings of another email service similar to Hotmail's. "Whatever it is, it is totally inexcusable," the source says.

A Webmaster for another high-profile email service, who also asked for anonymity, agrees the Hotmail crack bears the markings of insider knowledge. "This smacks of an inside job," says the Webmaster. "It doesn't look like the sort of thing that someone would have stumbled across and the quickest route to this exploit would be inside knowledge."

Both sources believe it may never be possible to trace those responsible for the security breach, or the people who used it. They agree that the whole Hotmail system should be overhauled. The security source says, "They may have server logs showing who has used this crack, but the very size of Hotmail may mean it is impossible to know who accessed whose accounts. It will also probably take a complete overhaul of the system for Hotmail to regain any credibility."

But Microsoft, perhaps misjudging the PR impact of the attack, denies an inside job was responsible for the "glitch" and confirms no overhaul of the Hotmail system is planned.

Gillian Kent, group marketing manager for MSN, is confident the Swedish hacking group claiming responsibility for the crack are the real culprits. "To our knowledge this was nobody internal. We will work with the local authorities to bring these malicious hackers to book. We see this as a glitch and it will not require Hotmail to be reconstructed." Kent, clearly exhausted by an early morning media blitz, denies there was anything "inexcusable" about Monday's events. "This could have happened to any email service. We've rectified the problem and the important thing is that people can feel confident in using Hotmail," she says.

This exploit, or variants of it, can still be found on a number of US and UK Web sites although shortly after it became common knowledge Monday afternoon, a number of these sites were removed.

Was this a "glitch"?

Do you feel confident in using Hotmail?

Tell the Mailroom

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
64 out of 109 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Service Delivery Manager - Customer Development & Food solutions - IT Manager - St. David\'s Park, Teeside , North West

Recognises, and actively seeks ways to exploit information technology to address complex business, organisational and technical issues, of both a ...

Web Applications Developer

NET (VB Script/ C#), JavaScript, XHTML, CSS, XML etc) are required as well as proficiency in the Adobe Studio CS3 Suite, Visual Studio and MS Office. ...

Associate Director of Business Intelligence

You will represent the Trust on local, regional and national professional forums and will ensure that the Trust is well positioned to exploit any ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment