
'Hotmail user data was never in danger'... 'OK... well maybe just a bit...'
Published: 13 August 2001 12:40 GMT
Microsoft has admitted that Hotmail user data may have been compromised by the Code Red worm, despite earlier assurances that this could not have happened.
It was only last Wednesday that the software giant categorically stated no customer data had been placed in jeapordy after the worm infected two of its servers.
A Microsoft spokesman said at the time: "No customer data was compromised and there was no impact in performance or security."
However, silicon.com has discovered that Hotmail was actually attacked by a variant of Code Red - not the original version. This worked in a slightly different way from its predecessor, and would have opened up a backdoor to the Hotmail servers.
One silicon.com reader - Jonathon Rickman, from security research and incident response team X Corps Security - said even though he supplied Microsoft with evidence which showed Hotmail's compromised system was attacking his, the company ignored him.
The log data from his company's servers shows that the Hotmail system was vulnerabe for over 11 hours on 6 August - and according to Rickman, Microsoft cannot offer a cast iron guarantee that the data was not compromised during that time.
Rickman said: "Microsoft claimed to have discovered the problem on Wednesday afternoon. Bunk! I notified them Monday. Microsoft needs to either tell the whole story, or nothing at all."
However, a spokesman for Microsoft UK said he believes no data was compromised. Two of the 4,000 Hotmail servers were infected, he confirmed, and added that it is "reasonable to assume one of the [infected] machines may have contained user data".
For related news see:
Hotmail falls to Code Red
http://www.silicon.com/a46400
Code Red: Still rearing its ugly head
http://www.silicon.com/a46355
BT systems crash - Code Red attack suspected
http://www.silicon.com/a46325
Basic awareness of computer based network attack scenarios.Desirable Experience: Detailed understanding of networking protocols. Moderate awareness ...
Delivering informal training for; new products existing products and their implementations new and existing generic technologies Providing mentoring, ...
If you hear nothing from us in 5 days please assume you have been unsuccessful on this occasion. Problem and Incident Management. Job ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you
Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business