Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old April 24th, 2012, 10:16 AM
STONEMAN's Avatar
STONEMAN STONEMAN is offline
Regular Poster
 
Join Date: Jan 2009
Location: London,South Of The River
Posts: 91
Default Re: 0day Exploit In hotmail

yep,this happened to me friday
__________________
Windows 7 64bit
Appguard---Sandboxie
Shadowdefender---Looknstop Firewall
  #27  
Old April 26th, 2012, 09:01 AM
kaioo kaioo is offline
Infrequent Poster
 
Join Date: Apr 2012
Location: DE
Posts: 2
Post Critical 0-Day in Hotmail Exploited in the Wild, Microsoft Issues Fix

Quote:
Security researchers from the Vulnerability Lab identified a critical password reset and setup flaw in Microsoft’s Hotmail service. As it turns out, cybercriminals also found the same weakness and quickly saw a big profit in it, but thanks to experts from the Lab and Microsoft's Security Response Center a fix was issued to prevent abuse.

According to WhiteC0de, the flaw was also detected by a hacker from Saudi Arabia. The details of the hack got leaked on an underground forum where the hacking service was advertised for $20 (15 EUR) per hacked Hotmail/Live account.

In a matter of days, a number of Hotmail accounts were hijacked by cybercriminals, presumably from Morocco, who were in possession of the remote exploit.

Fortunately for Microsoft, experts from the Vulnerability Lab, independently found the same flaw on April 10. The Redmond company was notified on April 20 and rushed to issue a temporary fix the same day.

A patch was released a few days later, before massive damage could be done by the cybercriminals.

“Remote attackers now get redirected to an exception page when they try to manipulate the session to reset passwords,” Benjamin Kunz Mejri, the CEO and founder of the Vulnerability Lab, explained.

“The vulnerability has been located, we notified them and the public attacks have been prevented by MSRC. We informed Microsoft regarding the vulnerability with detailed information.”

So let’s take a better look at the vulnerability present in the password reset functionality of the MSN Hotmail service.

The security vulnerability allowed remote attackers to bypass the recovery feature to set up a new arbitrary password. Token-based protection was in place, but it only checked if the input value was empty before closing or blocking the session.

This allowed the attacker to use context like “+++)-“ to bypass the security feature. An attacker could decode the CAPTCHA and send automated values over to the MSN Hotmail module, successful exploitation resulting in unauthorized MSN or Hotmail account access.

Here’s how the researcher recreated the attack technique to identify the vulnerability, as described by him.

Exploitation Techique(s):
- Bypass the Recovery Mod Page to New Pass or Reset;
- Bypass token protection via not empty value or positive value(s);
- Setup new password;
- Decode CAPTCHA and send automatic values.

If utilized in combination with a web exploit kit, the flaws could have been leveraged to automatically reset Hotmail or MSN Live accounts. MSRC made sure the problem no longer represents a threat, the account hijacking attacks being blocked.

“We are aware of this issue from public discussion, and we have already addressed it to protect Windows Live ID customers,” MSRC representatives said.

URL:
http://news.softpedia.com/news/Criti...x-266506.shtml
http://news.hitb.org/content/0day-re...otmail-patched

good work!
  #28  
Old April 26th, 2012, 12:45 PM
STONEMAN's Avatar
STONEMAN STONEMAN is offline
Regular Poster
 
Join Date: Jan 2009
Location: London,South Of The River
Posts: 91
Default Re: 0day Exploit In hotmail

thanks for this.
__________________
Windows 7 64bit
Appguard---Sandboxie
Shadowdefender---Looknstop Firewall
  #29  
Old April 27th, 2012, 11:58 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,255
Post Re: 0day Exploit In hotmail

Microsoft has patched the exploit
  #30  
Old April 28th, 2012, 07:59 AM
STONEMAN's Avatar
STONEMAN STONEMAN is offline
Regular Poster
 
Join Date: Jan 2009
Location: London,South Of The River
Posts: 91
Default Re: 0day Exploit In hotmail

Quote:
Originally Posted by siljaline
Microsoft has patched the exploit
yes,I noticed that they had,thank you.
__________________
Windows 7 64bit
Appguard---Sandboxie
Shadowdefender---Looknstop Firewall
  #31  
Old April 28th, 2012, 05:15 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,255
Post Re: 0day Exploit In hotmail

Cheers ~

Quote:
Originally Posted by STONEMAN
yes,I noticed that they had,thank you.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:55 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums