All the latest UK technology news, reviews and analysis

Spammers exploit Hotmail hole

by James Middleton

10 Jun 2003

Comment: 1

  • Tweet this

Spammers are exploiting a little known vulnerability in Microsoft's Hotmail service to send more junk mail automatically.

According to an advisory posted last weekend by Chip Rosenthal, of US systems developer Unicom, spammers have cracked the Distributed Authoring and Versioning (WebDav) interface which is used to send email to the Hotmail servers.

Although Rosenthal concedes that the small amount of spam coming through with a Dav message header suggests that only a few spammers have exploited the vulnerability, he believes that it is only a matter of time before others catch on.

"Hotmail has always been a problematic spam source," he said. "The saving grace has been that the spam had to be transmitted manually through a web form, so the send rate was limited by how fast the spammer could cut and paste."

But with the WebDav interface, spammers can script a junk mail run automatically and increase the amount of spam they can send out.

"Microsoft is allowing anybody to relay email - with forged headers, no less! - through the Hotmail servers," said Rosenthal.

The software giant has taken steps since evidence of the WebDav flaw first appeared in March.

It has limited the number of email addresses a user can target to 100 in any 24-hour period, and has upgraded Hotmail with extra anti-spam tools.

But Rosenthal warned that as more spammers learn of the vulnerability the deluge of spam will increase.

Microsoft was contacted but unable to comment.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Desktop Deployment Support Analyst (Worksite, SQL)

Desktop Deployment Support Analyst (Worksite, SQL...

Project Manager

Project Manager is required by Bank in Germany Suitable...

Web Developer / Web Designer Mobile & Social Media Application

Mobile & Social Media Application Web Developer...

CCVP Consultant

CCVP Consultant - Telecoms Cisco Certified Voice Professional...

To send to more than one email address, simply separate each address with a comma.