Date: Wed, 5 May 1999 17:31:34 -0500 From: David L. Nicol To: BUGTRAQ@netspace.org Subject: hotmail claims vulnerability patched, so here it is Dear Paul: I am reading your previous article on hotmail security, http://www.news.com/News/Item/0,4,33996,00.html and I'm CCing this message to the bugtraq list. A good patch from Hotmail would have to involve some additional info with the cookie. A couple of approaches that come to mind include: verifying http_referer data in the script submission to make sure its from the expected hotmail page putting additional hidden key fields with constantly changing names and values on submittalbe pages, to provide verification that the pages are legit investigating any incidents of pages being submitted with incorrect, nonexistent, or unexpected "secret flag fields" as described above I don't work for hotmail (as you know) and I am caught up in this as a bystander; I would expect hotmail to give you a explanation of their patch that not only is detailed but makes sense and that you cannot find a hole in. If hotmail merely changed the names of variables, or did a similar short term fix, the next expolit might not be nice enough to announce itself as such. Modifying the attached El Lite exploit to only work if it had a particular hotmail account might be a piece of cake; allowing for some highly targeted kinds of attacks. (esp. if a hotmail user is doing anything involving return-email verification, like tipjar or first virtual.) Here is the hacker's tripod page, including the exploit that takes advantage of the trust hotmail has for instructions from your browser, by secretly sending instructions to hotmail to change your password to


  Uno de los mejores correos gratis que existen es precisamente el que
  tu estás usando, hotmail. Su seguridad e inviolabilidad son ya
legendarias.

  Tanto es así que mira por donde a partir de este mismísimo momento las
  cosas van a tomar otro cariz. Quiero decir que lamentándolo mucho tu
  dirección de hotmail ha sido inutilizada, o mejor dicho, secuestrada
por mi.

  Ya nunca mas podrás entrar en ella.

  Así de definitivo. Ahora es

                                SOLO MIAAA!!!! :-))))

  Como soy un buenazo y no eres mi única víctima pues un dia de estos
voy a
  publicar en es.comp.hackers la password que os puse (es la misma para
todos
  vosotros pardillos)

  Hala, que te sea leve

  El Lite©