Actually guy was from my homestate of NJ and the whole reason the hack was
made possible was becuase Microsoft took off thier password checking for
thier Passport program. So his shortcut used an url that happened to not
check passwords anymore.


Bob Everland

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Christopher
Thompson
Sent: Friday, September 10, 1999 3:45 PM
To: [EMAIL PROTECTED]
Subject: [IMail Forum] Hotmail hack


Anyone know if IMail's URL string that is used for session management has
ever been hacked?  Some of you might be interested in the following blurb
about a Hotmail exploit.

1 September 1999 What Made Hotmail so Vulnerable?
The Hotmail hole appears to be a modified version of a program that was
written by a programmer at a Swedish Web design company so as to enable
users to access their Hotmail accounts easily. The application was
saving privileged information in the url.
http://www.zdnet.com/filters/printerfriendly/0,6061,2325838-79,00.html

                                       CDT

Chief Web Architect
WeAlumni.com


-----------------------------------------------------------
Find old friends... make new ones.  http://www.WeAlumni.com
Personalized e-mail, chat, contact book, calendar, & community -- FREE!
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to