main

Microsoft patches Hotmail vulnerability

malebolgia   on 15 October 2003 - 18:21 · 12 comments & 663 views

Advertisement (Why?)
Security company Finjan Software Inc. detected a security vulnerability in Microsoft Corp.'s Hotmail Web-based e-mail service, which Microsoft has since closed, the companies said Wednesday. The new security flaw, known as a cross-site scripting vulnerability, could be used to create an Internet worm that steals e-mail addresses from Hotmail users' accounts, captures credit card numbers or installs Trojan horse programs, Finjan said. The vulnerability exists in the way that Hotmail treats e-mail containing ActiveX controls, which are small, portable pieces of software code that enable programmers to embed sophisticated user interface elements into Web pages for use over a corporate intranet or the Internet. Hotmail content filters do not adequately block e-mail messages containing the controls, Finjan said.

In cross-site scripting attacks, malicious hackers embed attack code in Web pages or HTML e-mail messages. Once executed, cross-site scripting attacks can give attackers access to personal account or financial information or control over a remote machine. As a result of the Hotmail vulnerability, attackers could run malicious code on the computer of a Hotmail user who opened an e-mail containing the malicious ActiveX control, Finjan said. By embedding a worm engine in the e-mail and code that would grab the addresses from the Hotmail user's address books, attackers could use the Hotmail vulnerability to make a worm, Finjan said. A Microsoft spokesman said the company was informed of the problem by Finjan on Sept. 8 and patched the company's Hotmail systems within 24 hours. No Hotmail users were affected by the cross-site scripting vulnerability, which no longer affects Hotmail users, he said.

News source: InfoWorld


Pocket RAR at a glance:

* Pocket RAR is a version of the RAR archiver for the Pocket PC 2002
platform
* The Pocket RAR archiver is distributed as freeware. Anyone may use
this software freely.
* Pocket RAR is making smaller archives than the competition, saving
disk space and transmission time.
* Pocket RAR offers a graphic interactive interface utilizing pen
and menus. You can easily browse for archives and files using the
file- and archive management mode.
* Pocket RAR can compress, decompress and delete files in RAR & ZIP
archives.
* Pocket RAR provides advanced support for RAR archives with solid
archiving, multivolume archive support,six different compression
levels, Unicode in file names and password protection using 128 bit
AES encryption.
* Pocket RAR has a small executable size to reduce the amount of
precious Pocket PC memory occupied by the archiver.
* All advanced functions can be performed on a desktop computer using
WinRAR. Help files and install documentation are also stored on the
desktop computer.
* Pocket RAR allows for easy transfer of files between desktop computer
and Pocket PC.
* Pocket RAR features are constantly being developed to keep Pocket RAR
ahead of the pack.


Post a comment · Send to friend Comments · There are 12 additional comments
#1 CoLdFuSi0n on 15 Oct 2003 - 18:24
#2 apa1exakis on 15 Oct 2003 - 19:22
Good job to MS for fixin it so quick instead of denyin it or calling it to not be that important.
(2 replies) #3 IdobI on 15 Oct 2003 - 19:48
Important fact: Finjan = an Israeli Company
#3.1 PROGAME on 15 Oct 2003 - 19:57
hehe i felt it's important too
#3.2 mipra on 14 May 2004 - 02:05
(1 reply) #4 Avenger on 15 Oct 2003 - 21:04
Ironic that an Israeli company was looking for error & problems in Microsoft software when Israel itself has cut off all deals with Microsoft products in the country.
#4.1 machorro on 15 Oct 2003 - 21:26
its a private company not the goverment...
(1 reply) #5 SimplyPotatoes on 16 Oct 2003 - 00:01
boooo
#5.1 mipra on 14 May 2004 - 02:06
(1 reply) #6 chuayw2000 on 16 Oct 2003 - 11:00
A vulnerability in a non software stuff. How "pro" of microsoft.
#6.1 JaggedFlame on 16 Oct 2003 - 14:42
Hotmail isn't software? What would you call it, hardware?
#7 mipra on 14 May 2004 - 02:06
this is "new"..hehe..MS actually releases patches...

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)