Advertisement
Promo

Security threats Toolkit

Hackers gain free access to MSN Premium

Wang Dan and Hai Li CNETAsia

Published: 27 Feb 2004 08:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw in Microsoft's MSN Explorer software has allowed some Web surfers to gain free access to features and services that normally cost $9.95 (£5.35) a month, the software giant confirmed on Thursday.

Programmers in mainland China discovered the flaw sometime last year, a source familiar with the exploit told ZDNet China. This person, who spoke on condition of anonymity, said Chinese hackers have successfully created MSN Explorer 9 premium accounts that provide free access to 30MB of online storage and a 25MB email in-box, as well as to applications such as MSN Money Plus.

The exploit takes advantage of a modified installation file in MSN Explorer 8.5 that allows Web surfers to upgrade to MSN Explorer 9 by using fake high-speed Internet accounts from Verizon Communications. The crack grants free access to MSN Explorer 9 premium services that come bundled with Verizon's DSL (digital subscriber line) service under a co-marketing deal struck in 2002. Verizon DSL and MSN premium services are not currently marketed in China.

A Microsoft representative said the exploit poses no security threat, nor does it jeopardise subscriber information. He added that Microsoft and Verizon are taking "immediate steps" to fix the problem.

"There is no customer impact whatsoever," the Microsoft representative said in an email. "It is a case of users exploiting and taking advantage of a hole."

The flaw comes to light as MSN seeks to shift its businesses from dial-up Internet access to high-end broadband services. Microsoft currently counts about 9 million subscribers. But it has recently lost dial-up customers to high-speed access rivals, leading it to focus its efforts on broadband customers who get their connections from third parties such as Verizon. MSN's competitors, including America Online and Yahoo, have also been developing and marketing similar products.

ZDNet China's Hai Li and Wang Dan reported from Beijing. CNET News.com's Jim Hu contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
79 out of 161 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters