Subscribe to Windows IT Pro
May 09, 2003 12:00 AM

Hotmail and .NET Passport Open to Account Theft?

Windows IT Pro
InstantDoc ID #39001
Rating: (3)

According to a message posted by Muhammad Faisal Rauf Danka to the Bugtraq mailing list, Microsoft's .NET Passport service is wide open to attack by using a Passport user's Hotmail account to reset the password.

Danka claims to have found a certain Passport URL that anyone can enter into a Web browser and thereby hijack a user's Passport account. According to Danka, by tweaking the email address variables of the URL a password change confirmation message can be sent to a specified email address instead of the Passport account owner's email address. The email message contains another URL, and when a potential account hijacker clicks it, he or she can reset the Passport logon password. This effectively bypasses Passport's security checks that requires users to answer specific questions before being allowed to reset an account password. With the account password in hand, the hijacker then has complete access to the user's Passport account.

Danka said he discovered the vulnerability on April 12 and has tried since then to notify Hotmail of the problem by sending email to various email addresses but has received no response so far. I wonder if Danka realizes that Hotmail is a Microsoft product and that Microsoft has well-known methods for the public to notify them of security vulnerabilities? If you discover security problems in any Microsoft products or services, visit the TechNet Web site where you can notify the company of your concerns.

Microsoft quickly reacted to the vulnerability by removing access to the URL described by Danka. Users reported that the vulnerability appeared to affect older Passport accounts, but not any newer accounts. Microsoft has also disabled user accounts that appear to have been compromised by this specific attack. So as one mailing list reader pointed out, if you tried the exploit using your own Passport account, you might find that your account is now disabled. You'll need to work with Passport to reset your password.

Related Content:

ARTICLE TOOLS

Comments
  • Anonymous User
    7 years ago
    Jun 07, 2005

    bunch of noobs

  • Anonymous User
    7 years ago
    Apr 05, 2005

    I have suddenly lost access to my NET passport, my password is invalid and I cannot reset my password becuse my nationality seems to have changed as well. Is this some kind of hijack along those lines?

  • pratima
    8 years ago
    Jun 28, 2004

    i changed my password on a night i shouldn't have because now i cant remember it, and my secret question is so old i havent got clue what the answer is.. i need help!! plese.. the email address is my alternate one.. Thank you!!

  • robert fritz
    8 years ago
    Jun 15, 2004

    Your Comments (required):it is fine

  • kaleigh
    8 years ago
    Jun 13, 2004

    I changed my password on a night when I shouldnt have because now I cant remember it, and my secret question is so old that I havent got a clue what the answer is.... I need help!! Please.. The email address I used is my alternate one.. Thank you!!

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.