All the latest UK technology news, reviews and analysis

Hotmail users face mass spamming

by James Middleton

13 Aug 2001

Be the first to comment

  • Tweet this

Hotmail users were subjected to a mass spam attack this weekend, at the same time that it was revealed that a security glitch in the service allowed an attacker to hijack a user's Passport.

vnunet.com readers have reported mass mailings from a single address which managed to sneak past Hotmail's automatic junk mail filter. One user reported receiving over 8000 copies of the same 'Microsoft products at knock down prices' email.

Another user managed to paste the sender's address into the filtering system, but not before he was bombarded by over 1200 mails. "By the time I accessed the blocking filters and pasted in the rogue address I found that I had 1200+ emails. All emails came from one address and Hotmail's junk filter did not stop it," he told vnunet.com.

The discovery of a vulnerability in the Passport authentication system has also put user accounts at risk. Details of a cross scripting attack were published on security sites which would allow a malicious user to hijack the session cookie of another user, effectively stealing their identity.

A malicious JavaScript exploit embedded within an email as a URL can be used to trick the Passport system into passing the user's session cookie to a third party common gateway interface script on a remote server.

This attack is known as 'cross site scripting' and, although Microsoft has taken steps to filter out this type of attack, simply encoding the malicious script by replacing some letters with their hex equivalent will sneak the code through any filters. For example 68 is the hex value of h so the server would translate &x68;ttp:// into http://.

Once the attacker is in possession of the user's session cookie he can effectively masquerade as the true user and take control of all his accounts which use the Passport service.

A coder going by the name of Obscure, who wrote a white paper on the attack, said Microsoft has been informed of the situation. It is unclear whether the problem has yet been fixed.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

34%

1%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Group Services Manager - Telecoms

My client, a leading international name in Manufacturing...

Automated PHP Developer

My client is looking for an Automated Engineer/Developer...

Java Architect - IT Services - London

*** Java Architect - IT Services/Consultancy - London...

C# Developer, Software, London

Skills: C#, WCF, ASP.Net, Real Time Systems, MVC, SQL...

To send to more than one email address, simply separate each address with a comma.