Version: 2008

April 27, 2000 1:30 PM PDT

Microsoft zaps Hotmail password bug

  • Post a comment
Microsoft has patched a Hotmail bug that left users of the Web-based email service vulnerable to a password-stealing trick.

The exploit was the latest in a series devised by bug hunters using JavaScript to launch fraudulent password entry screens to trick people into handing over control of their accounts.

JavaScript is a Web scripting language designed to take actions on a Web site visitor's computer, such as launching a new window or scrolling text across the screen, without the visitor's interaction. After the first few password-stealing schemes came to light, Hotmail and other Web email providers decided to filter JavaScript from incoming messages.

But bug hunters have kept themselves busy finding ways to sneak the code around Hotmail's filters.

In the example addressed by Hotmail this week, Bulgarian bug hunter Georgi Guninski demonstrated a way to inject JavaScript through a style tag. The exploit worked only with Microsoft's Internet Explorer browser.

In response to news of the bug, Microsoft this week patched the Hotmail servers.

advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (0.55%) 0.17 31.17
Dow Jones Industrials (0.26%) 26.98 10,547.08
S&P 500 (0.12%) 1.30 1,127.78
NASDAQ (0.24%) 5.39 2,291.08
CNET TECH (0.26%) 4.25 1,662.16
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right