Go Back   The Scream! > ISP FORUMS > News

Reply
 
Thread Tools Display Modes
  #1  
Old 29-April-2012, 16:32
Scoobs's Avatar
Scoobs Scoobs is offline
 
Join Date: May 2001
Location: In my own little world
Posts: 4,896
News! Quick fix for Hotmail password bug

Microsoft has rushed out a fix for a serious bug in its Hotmail webmail services.

The bug allowed a hacker to reset the password for a Hotmail account, locking out its owner and giving the attacker access to the inbox.

The fix was put together because the bug was starting to be actively exploited online.

One security news site reported that some hackers were offering to hack Hotmail accounts for $20 (£12).

Computer security researchers discovered the vulnerability in early April and told Microsoft about it soon afterwards. The bug revolved around the way Hotmail handles the data that must pass back and forth when a user wants to reset their password.

Details of the bug leaked out and led to attackers trying to find a way round it.

Using add-on tools for the Firefox browser, hackers realised they could tamper with the data passing between a user and Hotmail servers in a way that handed them control over an account they targeted.

As knowledge of the bug spread, some started offering to hack accounts for cash and others posted YouTube videos of Hotmail accounts being taken over in real time.

It is not clear how many Hotmail accounts have been hacked by attackers exploiting the bug. Those who have fallen victim will know because they will find they are locked out of their Hotmail account.

With the bug being "actively exploited", Microsoft found a way to fix it and updated Hotmail to close the loophole a day or so later. Now Hotmail servers return an error when attackers try to manipulate data exchanges.

Microsoft issued a short statement about the fix and said no further action was needed by customers.

Hotmail is the world's largest web-based email service and Microsoft claims that it has about 350 million users.

Source BBC
__________________
SG5 Short Url
........
Reply With Quote
  #2  
Old 02-May-2012, 16:51
Tia's Avatar
Tia Tia is offline
Screamette
 
Join Date: Oct 2003
Location: Southern UK
Posts: 3,038
Default Re: Quick fix for Hotmail password bug

tsk!
__________________
Smiles are infectious, start an epidemic today
Reply With Quote
Reply

Tags
bbc, cash, email, hacked, hacker, hackers, hotmail, line, mail, online, security, tools

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
talktalk connection password pompom TalkTalk 1 10-June-2009 20:38
Unofficial fix issued for Vista networking flaw gem Networking 0 25-November-2008 18:06
First UT2004 Patch Fix List Alnath Games 3 29-April-2004 02:19


All times are GMT +1. The time now is 13:22.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©1999-2012 The Scream!