20 Aug 2001
Underground hacker site root-core.com has released a graphical exploit tool for sneaking a glimpse at other users' Hotmail accounts.
The tool apparently exploits a glitch in the service which allows users to guess the message numbers of other people's accounts. Although slow going, the method can be quite effective and the development of a GUI tool, Hobo, has made hacking Hotmail even easier.
When logged into your Hotmail account, the URL displays a message number for the appropriate message you are viewing, and the username. By tinkering with these, it's possible to hit on an existing username and message number combination. This allows you to view, but not modify, other users' messages.
Hobo just simplifies the process of trying to exploit the URLs manually. It will only hit on a correct combination every now and again but, in the meantime, it promises to provide script kiddies and the technically curious with hours of entertainment.
Microsoft is aware of the hole, so it is not expected to remain for very long.
A detailed description of the hack can be found here, and the scanner can be found here.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Java / J2EE analyst programmer with experience of building...
Crystal Reports Developer London or Dublin £340 per day...
Our client is a major Broadcasting company seeking a...
Support Engineer required to work for leading Online...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?