• About Us
  • Search
  • Compatibility
  • Forums
  • Archive
  • Channels
  • Home
  • Search
  • Member List
  • Calendar
  • Help

Current time: 08-22-2008, 03:35 AM Hello There, Guest! (Login — Register)


Warp2Search - Your Daily Tech News Service / General Discussion / Warp2Search Hang Out / Hacking Hotmail trough XSS

Post Reply  Post Thread 
Threaded Mode | Linear Mode
Hacking Hotmail trough XSS
Author Message
Jackass
Posting Freak
*****


Posts: 3,215
Group: Registered
Joined: Dec 2005
Status: Offline
Reputation: 0
Post: #1
Hacking Hotmail trough XSS

Quote:
Introduction
That microsoft's code is not always secure, is very clear again with this XSS exploit. This is not the first XSS exploit that has been found, others have been found. If you are viewing this document offline, the newest version can be found here. I am Adriaan Graas, a student who is interested in internet security and web development. I am currently 16 years old, though that would not make the exploit less effective.

Please do not mail me for hacking your ex-girlfriends inbox. Get away moron.

How
The idea is simple. When u are logged-in into Hotmail, a cookie is created wich allows you access every time you are in it's domain. Since the cookie is not IP-bind (how is this possible? - microsoft) we are able to fake the cookie, when stolen. Then use it to login. This all does mean that we do not have to know the password or even the emailaddress of the victim. Trough XSS we can insert an piece of javascript code that will send the cookie to a webserver with an log script. This can be written in PHP, ASP, CGI practically anything you want. The cookie can be faked with Proxomitron.

Adriaan Graas security and web development



I'm proud to be Canadian
07-06-2006 05:43 AM
Visit this user's website Find all posts by this user Quote this message in a reply
« Next Oldest | Next Newest »
Post Reply  Post Thread 

View a Printable Version
Send this Thread to a Friend
Subscribe to this Thread | Add Thread to Favorites

Forum Jump:

Contact Us | Warp2Search.Net | Return to Top | Return to Content | RSS Syndication

Powered By MyBB
Copyright © 2002-2008 MyBB Group