type in your query to search makeyougohmm
Things that ... make you go hmmtechnology music video art news reviews and muse on the web

June 6, 2005

No cookie love for I Love Messenger

spam — by TDavid @ 10:27 pm PST

A dutch programmer, Alex de Vries, discovered and disclosed a cross site scripting flaw with the MSN site ilovemessenger.msn.com which could have explosed Hotmail user email accounts to a malicious user. MSN flaw put Hotmail accounts at risk

Hotmail customers are no longer at risk, according to Microsoft. “The ‘I Love Messenger’ Web site has been disabled,” the company representative said in an e-mail statement. The site, which hosts emoticons, display pictures and backgrounds for MSN Messenger, Microsoft’s free instant messaging service, will be restored once the issue has been resolved…

The part that particularly caught my eye was the statement from the programmer who discovered the issue (follow the link in the ZDnet article to the programmer’s site):

Looks like MSN changed the exploitable page, so this exploit is not there anymore. But there is at least one other place known in MSN.com, where the same bug is still present.

Did the programmer tell Microsoft about this “one other place”? I hope so, but if not, then there is still an open exploit lingering at “one other place” on MSN. Be careful, Hotmail users.

Did this post make you go hmm?

F = please no more posts like thisD = not among your best stuffC = average postB = good post, I liked itA = great post, please create more like this (1 votes, average: 1 out of 5)

Loading ... Loading ...

RSS Feed comments for this post No Comments »

Your feedback is welcome below
TrackBack URI: http://www.makeyougohmm.com/20050606/1982/trackback/

Leave a comment


By leaving a comment you consent to the Official Hmm Comment Policy

Return Home


Copyright 2003-2008 KMR Enterprises All Rights Reserved