Details of a trick that opens up messages stored in any Hotmail account without the need for a password have been published online.
The information was produced by a group calling itself Root-Core and posted to its web site and security mailing lists over the weekend starting 18 August.
A Microsoft spokesperson says that engineers fixed the problem on August 19 and are also reviewing the security of Hotmail鈥檚 servers in light of the incident. Although Root-Core released a program that performed the attack automatically, Microsoft claims that the exploit was so difficult to execute that it posed little threat.
Advertisement
鈥淚t鈥檚 more of a proof of concept,鈥 a company spokeswoman told 快猫短视频. 鈥淚t would take thousands of attempts to get in.鈥
Other experts say it is a serious issue. 鈥淚t takes some time, but the fact that you can do this without any sort of authentication isn鈥檛 very good.鈥 says Gunter Ollman, principle consultant for Internet Security Systems.
However, David Litchfield, a consultant with computer security firm @Stake, says 鈥渋t should be fairly easy to fix.鈥
Open sesame
By customising a URL from within one Hotmail account, it is possible to read private messages that are stored in another, without needing a password. To target a specific people, their user names are required, but these are commonly exchanged, for example by those using instant messaging.
The exploit does not give complete access to an account and a six-digit number associated with each message has to be guessed. However, Root-Core released a program that carried out this guess-work automatically. Microsoft claims the exploit was further complicated because a victim had to be logged in at the same time.
There is a dispute over how the vulnerability was made public. A representative of Root-Core says that Microsoft engineers were alerted to the danger but ignored these warnings completely. Microsoft officials say that the company was left completely in the dark.
By Microsoft鈥檚 own estimations, Hotmail is the world most popular free email service, with 110 million users around the world. It is also part of Microsoft鈥檚 passport service, giving access to other personal services run by the company. Any security problem with Hotmail potentially affects these services too. It is just weeks since Microsoft was embarrassed when a computer worm managed to wriggle into the servers powering Hotmail. To make matters worse the worm exploited a software vulnerability in Microsoft鈥檚 own software, for which it had released a fix month earlier.