Spammers exploit Hotmail hole

Junk mailers breach WebDav implementation to generate more automatic spam

James Middleton

Spammers are exploiting a little known vulnerability in Microsoft's Hotmail service to send more junk mail automatically.

According to an advisory posted last weekend by Chip Rosenthal, of US systems developer Unicom, spammers have cracked the Distributed Authoring and Versioning (WebDav) interface which is used to send email to the Hotmail servers.

Advertisement

Although Rosenthal concedes that the small amount of spam coming through with a Dav message header suggests that only a few spammers have exploited the vulnerability, he believes that it is only a matter of time before others catch on.

"Hotmail has always been a problematic spam source," he said. "The saving grace has been that the spam had to be transmitted manually through a web form, so the send rate was limited by how fast the spammer could cut and paste."

But with the WebDav interface, spammers can script a junk mail run automatically and increase the amount of spam they can send out.

"Microsoft is allowing anybody to relay email - with forged headers, no less! - through the Hotmail servers," said Rosenthal.

The software giant has taken steps since evidence of the WebDav flaw first appeared in March.

It has limited the number of email addresses a user can target to 100 in any 24-hour period, and has upgraded Hotmail with extra anti-spam tools.

But Rosenthal warned that as more spammers learn of the vulnerability the deluge of spam will increase.

Microsoft was contacted but unable to comment.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

old computer

Government honours veterans of Bletchley Park at last

Surviving veterans of the code-breaking facility to receive badge of...

Motorola MC55 Enterprise Digital Assistant

Review: Motorola MC55 Enterprise Digital Assistant

A rugged Windows Mobile device for mobile workers

BT

BT promises 1.5m fibre connections by summer 2010

Telco begins major rollout in 69 locations across the UK

Primary Navigation