Hotmail Hole Could Expose Your Messages
Hacker group explains how to exploit a flaw in e-mail service, but it takes some guesswork and a lot of luck.
Jennifer DiSabatino, Computerworld
A limited though powerful hole in Hotmail allows hackers to view users' personal e-mail messages.
The hacker group Root Core has published an exploit of a vulnerability in Microsoft's free Web-based e-mail service that would allow a user to view the private e-mails of another user. However, attacks must be targeted to a specific user and require some careful guesswork.
Through a spokesperson, Microsoft says Hotmail engineers have identified the problem and are working to fix the hole. They hope to fix the flaw by the end of the day, she says.
There are two steps in the hack: First, hackers must find out the account name (e-mail address) of the Hotmail user; second, they must find out the exact time the message they want to read was sent.
The second step, however, is what makes this exploit difficult. Messages are time-stamped in what appears to be Unix time, or the number of seconds since January 1, 1970, according to Ryan Russell, an analyst at SecurityFocus.com, a business security Web site in San Mateo, California.
"It may help predict what these numbers are. It remains to be seen," he says. If a hacker knows approximately when a message was received, he can set up a program to calculate the seconds and run through messages in a given time frame to find an e-mail.
Hacker's Tips
The published exploit suggests such a solution. "Now [if] typing those message numbers manually is too much work, you could create a small utility to automatically scan [a] given range of messages from specific user name. (You need to build it to work with IE, as you must be logged in Hotmail when you want to view messages...)"
Much of the necessary information, however, appears to be missing from the published exploit, Russell says.
"It doesn't explain exactly how to guess the number of the message," Russell says, and at the Root Core Web site, "there has been little discussion on how hard it is."
The immediate concern for Hotmail users isn't grave, he says, since this is a targeted attack. Unlike other exploits, only one user at a time can be affected from a single hacker. He adds that Microsoft tends to fix these kinds of holes soon after they're publicized.
However, this exploit points out "the whole ASP model vulnerability," Russell says. "The good news is Microsoft can fix it in one fell swoop."
It is also difficult for security analysts to test the exploit, he says, because Microsoft could come after them for breaking into other e-mail accounts. "If they really want to know," he says, "They're going to have to put their neck on the line."
- Sponsored Resource:Improve your network with the right mix of features, performance and pricing.
- Sponsored Resource:Growing your business requires the right tools. Dell's networking servers can help.
- Sponsored Resource:Thinking about a new Laptop? Lenovo has models to meet everyone's needs.
- Sponsored Resource:Twitter: A how-to guide for using Twitter as a business tool.
- Sponsored Resource:Smartphone security threats are on the rise. Is it time to safegaurd your device?

For more enterprise computing news, visit Computerworld. Story copyright © 2007 Computerworld Inc. All rights reserved.
Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.
SMB Networking Center
Laptop Showcase
Featured APC Accessories For Your System
10% Off Entire Cart at Online Store
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.
People who read this also read:
Best Prices on Security Software
Norton Internet Security 2009 - 1 User/3 PCPrice: $29.97
Norton Internet Security 2009 - 1 User/1 PCPrice: $15.95
Norton 360Price: $25.00
Internet Security 2009Price: $15.99
Norton Internet Security 2009 - 1 User/3 PC, Small BoxPrice: $20.50
Internet Security 2009Price: $24.95
- 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
- Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.


