Microsoft squashes Hotmail hijack bug

Powered by SC Magazine
 

Accounts cracked in 60 seconds.

Microsoft has crushed a vulnerability in Hotmail that allowed attackers to hijack accounts using a Firefox extension.

The bug was actively exploited on cybercrime forums last month by users who boasted the ability to crack any Hotmail account in less than a minute.

Some charged around $20 for the service, security researcher Naveen Thakur said.

The attack was simplified through the Tamper Data Firefox extension, which helped hijackers exploit a weakness in the way Hotmail issued password resets. The exploit allowed attackers to bypass the recovery feature and issue a password of their choosing.

Researchers at Vulnerability Lab said the token system designed to secure the reset procedure "only checks if a value is empty then blocks or closes the web session".

"Successful exploitation results in unauthorised MSN or Hotmail account access."

Attackers could use positive values in the token system to bypass the security feature, decode the CAPTCHA anti-spam feature and send automated values to the MSN Live Hotmail module.

Vulnerability Labs discovered the flaw and reported it to Microsoft about ten days later.

Redmond's security team took only a day to fix the flaw.

Copyright © SC Magazine, Australia


Microsoft squashes Hotmail hijack bug
 
 
 
Top Stories
At the top of her game
A decision to bring digital operations back in-house three years ago has paid big dividends for Tabcorp.
 
Westpac hires SAP man as CTO
Creates four new IT lead positions.
 
Qld Transport to replace core registration system
State's biggest citizen info repository set for overhaul.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
More 4G from Optus in Darwin
Nov 21, 2014
Click to see where Optus has expanded coverage to the suburbs near Darwin.
Optus steps up regional 4G coverage
Nov 20, 2014
Once 700Mhz services are working, Optus claims regional users will have a "faster and more ...
This Huawei 4G phone costs $99
Nov 12, 2014
The $99 Huawei Ascend Y550, available through Vodafone, enters the budget market as one of the ...
4G smartphones: Microsoft's Lumia 830
Nov 7, 2014
Microsoft has announced its flagship Windows Phone, the Nokia Lumia 830 4G, will be available in ...
Do you direct debit customers? Read this
Oct 10, 2014
Authorities have been targeting direct debit practices with iiNet and Dodo receiving formal ...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  38%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  21%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 979

Vote