Donation Goal
Donate Now Goal amount for this year: 799 USD, Received: 100 USD (13%)
Please donate to help support this website. The funds will be used to purchase owned license of LiteSpeed Web Server Enterprise (2-CPU). It provides superior performance in terms of raw speed, scalability and anti-DDoS capabilities.

Hack Hotmail using XSS exploit

Posted By Raymond In Category: Computer

Jul
7
2006

Hack Hotmail XSS exploit
That microsoft’s code is not always secure, is very clear again with this XSS exploit. This is not the first XSS exploit that has been found, others have been found.

Sixteen year-old Adriaan Graas from The Netherlands informed Microsoft last week about an XSS (cross site scripting) exploit he found in Hotmail. The exploit allows hackers to steal cookies from their victims and obtain full control over their inboxes without the need of knowing their passwords.

The idea is simple. When you are logged-in into Hotmail, a cookie is created which allows you access every time you are in it’s domain. Since the cookie is not IP-bind (how is this possible? – microsoft) we are able to fake the cookie, when stolen. Then use it to login. This all does mean that we do not have to know the password or even the email address of the victim. Trough XSS we can insert an piece of javascript code that will send the cookie to a webserver with an log script. This can be written in PHP, ASP, CGI practically anything you want. The cookie can be faked with Proxomitron.

Read more…


Related posts:
  • Cancelling MSN Hotmail Plus service
  • Automatic Hotmail and MSN Registration
  • Unlimited download hack for RapidShare
  • Copyright © 2005-2012 - Raymond.CC Blog