You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft red faced over web-mail flaw

Getting hot in here...

Tags: hotmail, flaw, microsoft

By Joris Evers

Published: 7 June 2005 08:45 GMT

Microsoft took part of its MSN website offline over the weekend, after it learned of a flaw that could let an attacker gain access to Hotmail accounts, the company said.

The MSN website, http://ilovemessenger.msn.com/, contained a so-called cross-site scripting flaw, a Microsoft representative said on Monday. In its initial review of the issue, the company found that an attacker could use the vulnerability to obtain "cookies" from Hotmail users by getting them to click on a malicious URL. The cookies could then grant access to those email accounts, the representative said.

Cookies are small files stored on a computer that contain user data. Hotmail is one of the world's most popular web-based email services, with more than 200 million active accounts, according to Microsoft.

Microsoft's acknowledgement of the Hotmail issue comes after the security hole was disclosed on Saturday by Alex de Vries, a Dutch programmer, on the Net-Force website for security enthusiasts.

Cross-site scripting flaws are errors in website design, not in web browsers, and were discovered more than five years ago. Microsoft has described the flaws as serious security vulnerabilities.

Hotmail customers are no longer at risk, according to Microsoft. "The 'I Love Messenger' website has been disabled," the company representative said.

The site, which hosts emoticons and display pictures and backgrounds for MSN Messenger (Microsoft's free instant messaging service), will be restored once the issue has been resolved, according to the representative. On Monday afternoon (PT), the web address was redirecting users to the main MSN Messenger website.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Penetration Testers Required - Must be CREST / CHECK Accredited

Overview • To work in their security testing team, you will need a strong technical background in the area of network security including a ...

Senior Financial Systems AdminLeeds/Brum/Manc/LondonTo 53k

This is a role not to be missed so if you are interested in applying please forward your CV to gcoleshill@intelectplc.com or give me a call on 0161 ...

Account Manager

Running database updates or data campaign selections.The client expects the Account Manager to be highly organised and a strong documenterThis is a ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: