Microsoft Closes Major Hotmail, Passport, .Net Security Hole:

Search

Andersen celebrates his 39-yard NFC Championship w
Joined
Sep 21, 2004
Messages
1,789
Tokens
Microsoft Closes Major Hotmail, Passport, .Net Security Hole: Microsoft has closed a major Hotmail / Passport / .NET security hole that allowed remote attackers to reset the password on virtually any account with no need for any information other then the email address used.

A password reset form, available at the passport website, allowed users to request change information for their password. Unfortunately it also allowed any email address to be specified for where the information would be sent. This enabled remote attackers to specify a victim's email address and an address they controlled to which the password reset information would be sent. This web application has now been taken offline, closing the flaw.

Additionally there are other forms that allow for account password resetting, many of which rely on asking the user questions for which only the user knows the answer. Unfortunately many of these questions are weak, such as "what is your name?" or "what is your mother's maiden name?". Often times this information is publicly available and easy to find.
 

Forum statistics

Threads
1,108,228
Messages
13,449,768
Members
99,402
Latest member
jb52197
The RX is the sports betting industry's leading information portal for bonuses, picks, and sportsbook reviews. Find the best deals offered by a sportsbook in your state and browse our free picks section.FacebookTwitterInstagramContact Usforum@therx.com