Obscure hole could expose Hotmail messages

A limited though powerful hole in Hotmail allows hackers to view users' personal e-mail messages.

The hacker group Root Core has published an exploit of a vulnerability in Microsoft Corp.'s free Web-based e-mail service that would allow a user to view the private e-mails of another user. However, attacks must be targeted to a specific user and require some careful guesswork.

Through a spokeswoman, Microsoft said Hotmail engineers have identified the problem and are working to fix the hole. They hope to fix the flaw by the end of the day, she said.

There are two steps involving the hack: first, one must find out the account name (e-mail address) of the Hotmail user; second, you must find out the exact time the message you want to read was sent.

The second step, however, is what makes this exploit difficult. Messages are time-stamped in what appears to be Unix time, or the number of seconds since Jan. 1, 1970, according to Ryan Russell, an analyst at SecurityFocus.com, a business security Web site in San Mateo, California.

"It may help predict what these numbers are. It remains to be seen," he said. If a hacker knows approximately when a message was received, he can set up a program to calculate the seconds and run through messages in a given time frame to find an e-mail.

The published exploit suggests such a solution. "Now [if] typing those message numbers manually is too much work, you could create a small utility to automatically scan [a] given range of messages from specific user name. (You need to build it to work with IE, as you must be logged in Hotmail when you want to view messages...)" Much of the necessary information, however, appears to be missing from the published exploit, Russell said.

"It doesn't explain exactly how to guess the number of the message," Russell said, and at the Root Core Web site, "there has been little discussion on how hard it is."

The immediate concern for Hotmail users isn't grave, he said, since this is a targeted attack. Unlike other exploits, only one user at a time can be affected from a single hacker. He added that Microsoft tends to fix these kinds of holes soon after they're publicized.

However, this exploit points out, "the whole ASP model vulnerability," Russell said. "The good news is Microsoft can fix it in one fell swoop."

It is also difficult for security analysts to test the exploit, he said, since Microsoft could come after them for breaking into other e-mail accounts. "If they really want to know," he said, "They're going to have to put their neck on the line."

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?