MSN Contact List Disclosure Flaw!

Published by

Neowin.net Register an account for MSN messenger, make some contact email addresses, leave the account for 31 days. On a different machine (to ensure there's no cache), go to the sign up section of MSN messenger, sign up again, using the same screen name. You'll be able to see the previous user's contact list.

None of the contacts will have been alerted to the fact that the new username actully belong to an entirely different person, so they'll still be sending messages, and if the new user is a haxor, (s)he'll be replying just as if (s)he's the original user.

I alerted Microsoft on monday, and have received no reply. So there. Safer computing with M$? Thought so...