ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

New flaw discovered in MS Hotmail

Margaret Kane ZDNet US

Published: 10 May 2000 16:52 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Bennett Haselton, Webmaster for Peacefire.org, said the flaw involves sending a user an email with an HTML attachment. When the user clicks on the attachment, the file sends a copy of the user's cookie to the hacker.

Once that cookie is received, the hacker can insert it manually into the Netscape cookies.txt file and use that authentication key to log in to Hotmail as the user. Click here for a description of the trick.

Microsoft, which owns the Hotmail service, could not immediately be reached for comment

Since the cookie does not contain the user's password, the hacker can only access the account when the user is logged on and as long as the authentication code is valid. But Haselton said that five minutes would be long enough for a hacker with a prepared script to download all of a user's email messages.

The trick uses JavaScript to send the cookie. Hotmail filters JavaScript in regular email messages but doesn't filter JavaScript in HTML attachments.

"It's not a trivial bug that has to do with formatting; it's the essential nature of the software," Haselton said. "Hotmail is what all the big hunters set their sights on. ... Most of the free email services can be broken into, and you find a new way to do it every three weeks or so. But it's really scary that hobbyists are the ones who are doing this."

Haselton has discovered several bugs in the past, including a security flaw in the Eudora email program, and a Netscape exploit that allowed Webmasters to view users' bookmarks.

What do you think? Tell the Mailroom. And read what others have said.

Take me to Hackers

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
68 out of 159 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Sentry Posts Blog

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment

Government launches new e-crime unit

Ok, so this is outside of my main area of focus of sustainable and green tech but I do track some security issues too. I was at a meeting last week with Microsoft's security advisor... More

Post a comment