I can tell you that the url keys are not something easy to hack. I have been
working with this system and its pretty good. If you put in the correct keys
you may get in but they expire rather fast anyway, In my view i think that
they would never get the correct keys to get into someones mailbox unless
they had a few hours and software to send over 800 requests a second. Thus
overloading the imail webserver anyway. Grin

> -----Original Message-----
> From: Christopher Thompson [SMTP:[EMAIL PROTECTED]]
> Sent: Friday, September 10, 1999 1:45 PM
> To:   [EMAIL PROTECTED]
> Subject:      [IMail Forum] Hotmail hack
> 
> Anyone know if IMail's URL string that is used for session management has
> ever been hacked?  Some of you might be interested in the following blurb
> about a Hotmail exploit.
> 
> 1 September 1999 What Made Hotmail so Vulnerable?
> The Hotmail hole appears to be a modified version of a program that was
> written by a programmer at a Swedish Web design company so as to enable
> users to access their Hotmail accounts easily. The application was
> saving privileged information in the url.
> http://www.zdnet.com/filters/printerfriendly/0,6061,2325838-79,00.html
> 
>                                        CDT
> 
> Chief Web Architect
> WeAlumni.com
> 
> 
> -----------------------------------------------------------
> Find old friends... make new ones.  http://www.WeAlumni.com
> Personalized e-mail, chat, contact book, calendar, & community -- FREE!
> Please visit http://www.ipswitch.com/support/mailing-lists.html 
> to be removed from this list.
Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to