• About Us
  • Search
  • Compatibility
  • Forums
  • Archive
  • Channels
  • Home
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
Warp2Search.net » News » February 2002 » Windows Messenger Security Issue Revealed?!

Windows Messenger Security Issue Revealed?!

Posted by: [PM] on: 02/05/2002 05:49 PM [ Print | 0 comment(s) ] · 1173 views

According to a BugTraq Mailing List Archive post by Richard Burton the messenger software MSN Messenger (and Windows Messenger on XP) can be used to obtain personal information about a user from any website (in any domain). Read more...



Using java script  a user's display name can be obtained from Messenger, as well as the display names of all their contacts. For users who have a sensible and accurate display name this should be considered a privacy issue. (Note: anyone who has not set a display name at all, will reveal their email address instead.) Using the same technique web sites hosted on certain domains (microsoft.com, hotmail.com & hotmail.msn.com) can also access the email address of the user (along with the email addresses of all their contacts). This could be used by Microsoft to track users on their sites, which many would consider to be a privacy issue. In addition to the three domains mentioned above, additional domains can be allowed access to the email addresses with a single registry entry. This registry entry could be made by spyware/adware installed by a user (sometimes unknowingly along with a piece of shareware). Once there you have the potential to give your email address to any site that requests it and places it in a cookie. Technical Info: Microsoft designed Messenger to allow functionality to be used in webpages using java script  or vb script . This includes the ability to view the display name and email address of the user and their contacts. In an attempt to protect users only a certain selection of sites can use script to get email addresses, but all can get display names. The list of domain suffixes that have full access to Messenger functionality (email addresses & more?) can be found in the registry in key "HKEY_LOCAL_MACHINE SOFTWARE Microsoft MessengerService Policies Suffixes".
Values "Suffix0", "Suffix1", etc. By default there are no entries in the list, but they can be added. E.g. adding value Suffix0 = "test.com" will give web sites in the test.com domain full access to Messenger information. Full domains do not have to be specified in the list, adding "com" would allow all .com sites to have full access. Although by default there are no entries in this list, three domains (listed above) are hard coded into Messenger for the same purpose. These allow Microsoft to make their sites (e.g. Hotmail) look nice by integrating messenger features into them. The user cannot remove the special status applied to these sites. The only way for a user to prevent sites having any access to their information is by logging out of Messenger before visiting. For a simple how-to, just look at the source of the demonstration page given below. Test your Messenger


Digg it! Del.icio.us Technorati Furl Google Bookmarks

« Maxtor Goes USB 2.0 & Firewire! · Windows Messenger Security Issue Revealed?! · Intel Introduces L3 Cache On Die With McKinley Processor! »

Warp2Search.net » News » February 2002 » Windows Messenger Security Issue Revealed?!

Latest News

· Opera 10.10 Final
· NZXT Guardian 921 PC Case Review
· ATI Catalyst 9.11 Windows 7 Driver Analysis
· NZXT M59 Mid-Tower Computer Case Review
· Opera (BETA) 10.10 (Build 1893)
· GMER 1.0.15.15252
· Windows Home Server Power Pack 3: November 24
· MemSet 4.1
· SetFSB 2.2.134.98
· ProduKey 1.40
· Hiren's BootCD 10.1
· FinalBurner Free 2.15.0.171
· Replay Music 3.92
· Google Chrome BETA 4.0.249.4
· Sapphire 5970 Cfx and HIS 5970 CFx Review
· Ultra X4 500 W Power Supply Review
· PC Tools ThreatFire 4.7.0.9
· ZipGenius 6.2.0.2000

Community Forum

· S.T.A.L.K.E.R.: Call of Pripyat Benchmark
Posted by Regeneration

· Thermaltake BlacX Duet Dual Hard Drive Docking Station Review @ Tweaknews
Posted by Tweaknews

· Noctua NH-D14 Premium CPU Cooler Review @ Clunk.org.uk
Posted by Clunk

· HIS Radeon HD4850 iCooler 1GB Videocard Review @ Tweaknews
Posted by Tweaknews

· Building An Ultimate Gaming Machine!
Posted by ezone


Nodes To Friends





Online Users

There are currently 458 user(s) online:
Google, Live Search, MSN, Yahoo

© 2007-2009 Esselbach Internet Solutions
All products mentioned are registered trademarks or trademarks of their respective owners.
Read our disclaimer over here and our Privacy Policy over here
Managed with Contentteller(R) Business Edition, (C) 2002 - 2009 Esselbach Internet Solutions