Real-time AntiSpam protection, automated and self-managed content filtering
Black Green Blue Red Gold
RSS
  • Home PageHome
  • About
  • Downloads
  • Store
  • Support
  • Contact

Old IE Means New Hotmail Vulnerability

Net Progress Add comments
Hotmail Users Need to Update Browser For many people, the axiom, "If it ain't broke, don't fix it", is their modus operandi. With so many other things to worry about, updating a browser that seems to be working fine just isn't a high priority. However, a recently discovered security bug in Hotmail may serve as a wakeup call to all Internet Explorer 4.x and 5.0 users. BugNet has verified a security vulnerability that would allow a malicious user to usurp control of someone else's Hotmail account, allowing the hacker to read and to send e-mail from that account. Because this security hole can be thwarted by upgrading IE, we recommend that all Hotmail users verify that they are running the most current version of the Microsoft

browser.? With testing provided by KeyLabs, BugNet was able to verify this Hotmail vulnerability reported by an Internet developer in Denizli, Turkey. Alp Sinan, an e-commerce and security consultant, supplied demonstration code that allowed us to gain access to test e-mail accounts on the Hotmail server. The exploit involves using a previously reported security hole in IE ("Unauthorized Cookie Access") to steal an unsuspecting user's Hotmail cookie. That cookie is then used to authenticate the malicious user to the victim's Hotmail account. While newer versions of IE prevent a hacker from stealing cookies, there are still a lot of Internet users that use the default browser that came with the Windows 95 and Windows 98. For many, the size of the download has prevented them from upgrading over a dialup connection. Since Microsoft has issued Service Packs and Upgrades for the "Unauthorized Cookie Access" bug, this leaves the rest of the blame with Hotmail for their lax security and authentication procedures. Hotmail's authentication is built on session cookies. When a user logs in, Hotmail sends the user an encoded cookie that the browser uses to authenticate with the Hotmail server throughout the life of the Hotmail session. If the user can be tricked into sending this session cookie to a hacker, then the hacker could also gain access to the victim's account. The hacker might do this by enticing the user to click on a carefully constructed Internet link within an e-mail or on a web page. BugNet informed Hotmail of the vulnerability and included sample code. To date we have not received any feedback. Until Hotmail changes it's security mechanism, the only fix is to update IE to versions 5.1 with Service Pack 1, or to upgrade IE to version 5.5. Both of these are freely downloadable from Microsoft's site. Stay tuned for more information as it becomes available.

August 18th, 2009  
Tags: bug, BugNet, dialup connection, hacker, Hotmail, Hotmail session, New Hotmail Vulnerability

Leave a Reply

  • Menu

    • About
    • Contact
    • Downloads
      • List Servers and SMTP Servers
      • Small Business
      • Veriat Enterprise
    • Store
    • Support
  • Categories

    • Anti-Comment Spam Tactics
    • Anti-spam appliances
    • Anti-spam techniques
    • Bug fixing
    • Bug Info
    • Comments
    • Digital Signature
    • Net Progress
    • News
    • Review
    • Spam Facts
    • Spam filtering techniques
    • Spam wars
    • Uncategorized
  • Archives

    • May 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • April 2009
  • Tags

    abusive templates America Online anti spam antispam Anti Spam Web BugNet Data Protection Data Protection Agency Digital ID e-mail e-mails email FTP gold spammers Groupware groupware system hacker Internet Internet Explorer Internet providers Internet service Internet Users Intranet Intranet bets pay off Intranets Rescue Reengineering junk mail LDAP LotRO macro Microsoft NDS NetBIOS Netscape Java Hole Netscape Navigator operating system QuitaSpam spam spammer spammers spam messages spyware Veriat Digital ID Water Windows 95 World of Warcraft
  •  

    July 2010
    M T W T F S S
    « May    
     1234
    567891011
    12131415161718
    19202122232425
    262728293031  
  • Blogroll

    • Call Center
    • Direct Buy
    • free software download
    • Internet Security
    • joomla templates
    • Laser Hair Removal
    • ovulation calendar
    • Technical Schools
    • Word to PDF
    • zero emission vehicle
Categories
  • Anti-Comment Spam Tactics
  • Anti-spam appliances
  • Anti-spam techniques
  • Bug fixing
  • Bug Info
  • Comments
  • Digital Signature
  • Net Progress
  • News
  • Review
  • Spam Facts
  • Spam filtering techniques
  • Spam wars
  • Uncategorized

A Veriat Digital ID establishes your identity to others that you communicate with. Digital IDs contain a unique digital code which can be used to verify your digital signature or encrypt messages.Read more

Copyright © 2010 Real-time AntiSpam protection, automated and self-managed content filtering All Rights Reserved XHTML CSS