Excite in web mail hijack drama

Portal leaves users' mail exposed

James Middleton

Security watchers have identified a vulnerability in the web mail service of internet portal Excite that allows for the hijacking of a user's account.

According to the experts, when a user logs in to their account through Excite's web interface, the session is authenticated by a unique URL.

Advertisement

By sending an HTML email which includes an image based on another server to the victim, an attacker can easily get the unique URL from the referrer field in the HTTP header.

Simply pasting this into a web browser would drop the attacker straight into the victim's mailbox with complete control of the account.

The exploit has been discussed to some degree on security mailing list Bugtraq, and Eyeonsecurity.net has even published a demonstration of the attack. Excite has been notified but has not yet responded.

By way of combating the threat, Eyeonsecurity recommends using secure mode in the browser (HTTPS) to access Excite web mail. This prevents the referrer URL from being sent out.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

HTC Hero

Video: HTC Hero launch

Handset maker unveils its latest Android-based smartphone

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

firefox logo

In Pictures: Firefox 3.5

Screenshots from Mozilla's latest Firefox web browser

BT

BT scraps Phorm rollout

Telco claims to be too tight on resources to support...

Nokia

Nokia denies Android smartphone rumours

Mobile phone giant insists it will stick with Symbian

Second Life

Second Life seeks to mix the real and virtual worlds

Linden Lab unveils plans to integrate with social networks and...

Primary Navigation