Users login

Create an account »

JOIN XATRIX

Users login

Home » Hacking News » Hotmail three stage exploit

Hotmail three stage exploit

by Nikola Strahija on June 9th, 2005 Only few days after MSN Korea hack Microsoft has a problem again a cross site scripting flaw


A cookie manipulation exploit that created a possible means for hackers to break into Hotmail accounts forced Microsoft into pulling a portion of its website last weekend.

The exploitable page - http://ilovemessenger.msn.com - has been updated to remove a cross site scripting flaw. But Alex de Vries, the Dutch security enthusiast who discovered the trick, warns that other portions of MSN's site are still vulnerable.

The exploit works in three stages. Hackers use security loopholes to inject hostile code onto MSN's web site. They can then harvest Hotmail cookies from surfers redirected to this contaminated page by taking advantage of the use of Hotmail cookies across the MSN.com domain. Once hackers have a victim's cookie they can use tools to trick Hotmail into thinking they already logged on as this user.

The security flaw comes days after Microsoft confessed its South Korean MSN Web site was the target of a hacking attack. Hackers succeeded in loading malicious code onto the site at part of an attack designed to steal passwords for Lineage, an on-line game popular in East Asia.


Newsletter signup

Signup to our monthly newsletter and stay in touch with IT news!

Free E-books

We've got ebooks! But they're not online. :( Please give us a few days to bring downloads back.

Contact

Have something to say or just wanna drop us a line? Please keep this in mind: to spam, we reply with spam.

Contact us »