Microsoft squashes Hotmail hijack bug

Powered by SC Magazine
 

Accounts cracked in 60 seconds.

Microsoft has crushed a vulnerability in Hotmail that allowed attackers to hijack accounts using a Firefox extension.

The bug was actively exploited on cybercrime forums last month by users who boasted the ability to crack any Hotmail account in less than a minute.

Some charged around $20 for the service, security researcher Naveen Thakur said.

The attack was simplified through the Tamper Data Firefox extension, which helped hijackers exploit a weakness in the way Hotmail issued password resets. The exploit allowed attackers to bypass the recovery feature and issue a password of their choosing.

Researchers at Vulnerability Lab said the token system designed to secure the reset procedure "only checks if a value is empty then blocks or closes the web session".

"Successful exploitation results in unauthorised MSN or Hotmail account access."

Attackers could use positive values in the token system to bypass the security feature, decode the CAPTCHA anti-spam feature and send automated values to the MSN Live Hotmail module.

Vulnerability Labs discovered the flaw and reported it to Microsoft about ten days later.

Redmond's security team took only a day to fix the flaw.

Copyright © SC Magazine, Australia


Microsoft squashes Hotmail hijack bug
 
 
 
Top Stories
How hard do you hack back?
[Blog post] Taking the offensive could have unintended consequences.
 
Five zero-cost ways to improve MySQL performance
How to easily boost MySQL throughput by up to 5x.
 
The big winners from Defence’s back-office IT refresh
Updated: The full list of subcontractors.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
This 4G smartphone costs $219
Sep 3, 2014
It's possible to spend a lot less on a smartphone if you're prepared to go with a brand you ...
Looking for storage? Seagate has five new small business NAS devices
Aug 22, 2014
Seagate has announced a new portfolio of Networked Attached Storage (NAS) solutions specifically ...
Run a small business in western Sydney?
Aug 15, 2014
This event might be of interest if you're looking to meet other people with a similar interest ...
Buying a tablet? Microsoft's Surface Pro 3 goes on sale this month
Aug 8, 2014
Microsoft has announced its Surface Pro 3 will go on sale in Australia on 28 August from ...
Apple's top MacBook Pro with Retina is now cheaper
Aug 1, 2014
Apple has updated its MacBook Pro range with faster processors and new pricing, including ...
Latest Comments
Polls
Which is the most prevalent cyber attack method your organisation faces?




   |   View results
Phishing and social engineering
  68%
 
Advanced persistent threats
  3%
 
Unpatched or unsupported software vulnerabilities
  11%
 
Denial of service attacks
  6%
 
Insider threats
  12%
TOTAL VOTES: 1019

Vote