snowman
May 5th, 2002, 06:07 PM
* * * * Hotmail at Risk to Cookie Thieves
.
.
MSN Hotmail users, guard your cookies. A simple technique for accessing Microsoft's free e-mail service without a password is in the wild and apparently being exploited.
.
The trick involves capturing a copy of the victim's browser cookies file. Once the perpetrator gains two key Hotmail cookies, there's no way to lock him out because at Hotmail, cookies trump even passwords.
.
"What's scary about this is that once they have your cookies, they have your account forever. Even if you change your password, they can still get in," said Eric Glover, a New Jersey-based programmer who has a doctorate in computer science from the University of Michigan.
.
Glover said he unearthed the Hotmail cookie problem when a friend's former boss started accessing the friend's Hotmail account -- and continued to use the account even after the pal repeatedly changed her password.
.
After studying Hotmail's sign-on process, Glover concluded that the snoopy manager likely had grabbed a copy of the Hotmail cookies from the friend's work computer or a back-up tape and had been using them to digitally unlock her Web mail account.
.
Microsoft officials said Thursday that the Hotmail service offers users several tools to limit what the company terms "cookie-based replay attacks" but added that Microsoft is "always looking at ways to protect users further, as well as giving them more control over their online experience."
.
Security experts, however, said today that the Hotmail vulnerability exposes the risks of relying on browser cookies as the digital keys to Internet sites.
.
Cookies, the small data files placed on an Internet user's computer when visiting websites, are primarily used to identify visitors for the purpose of customizing content such as advertising. But many sites, including Hotmail, also rely on cookies for more serious authentication purposes.
.
For such sites, the cookie is akin to an ATM banking card that doesn't also require the holder to provide a password. Lose the "card" and you may give up your security....
.
. * * * * *
http://boards.cramsession.com/boards/vbm.asp?m=543274
* * * ** MODS, * if this is the in-corrected forum please feel free to move accordingly......thanks
* * * * * * * * * * * * *snowman
.
.
MSN Hotmail users, guard your cookies. A simple technique for accessing Microsoft's free e-mail service without a password is in the wild and apparently being exploited.
.
The trick involves capturing a copy of the victim's browser cookies file. Once the perpetrator gains two key Hotmail cookies, there's no way to lock him out because at Hotmail, cookies trump even passwords.
.
"What's scary about this is that once they have your cookies, they have your account forever. Even if you change your password, they can still get in," said Eric Glover, a New Jersey-based programmer who has a doctorate in computer science from the University of Michigan.
.
Glover said he unearthed the Hotmail cookie problem when a friend's former boss started accessing the friend's Hotmail account -- and continued to use the account even after the pal repeatedly changed her password.
.
After studying Hotmail's sign-on process, Glover concluded that the snoopy manager likely had grabbed a copy of the Hotmail cookies from the friend's work computer or a back-up tape and had been using them to digitally unlock her Web mail account.
.
Microsoft officials said Thursday that the Hotmail service offers users several tools to limit what the company terms "cookie-based replay attacks" but added that Microsoft is "always looking at ways to protect users further, as well as giving them more control over their online experience."
.
Security experts, however, said today that the Hotmail vulnerability exposes the risks of relying on browser cookies as the digital keys to Internet sites.
.
Cookies, the small data files placed on an Internet user's computer when visiting websites, are primarily used to identify visitors for the purpose of customizing content such as advertising. But many sites, including Hotmail, also rely on cookies for more serious authentication purposes.
.
For such sites, the cookie is akin to an ATM banking card that doesn't also require the holder to provide a password. Lose the "card" and you may give up your security....
.
. * * * * *
http://boards.cramsession.com/boards/vbm.asp?m=543274
* * * ** MODS, * if this is the in-corrected forum please feel free to move accordingly......thanks
* * * * * * * * * * * * *snowman