Wow... it's a little worse in KWM.  I just tried a test on the [EMAIL PROTECTED] address.  Since
the preview for the first message in the Inbox comes up automatically, you can't even read your other
mail.  It just forwards you to the faux login page as soon as you login.  The only way to read the
rest of your mail is to send yourself another message (so the preview for the malicious email doesn't
automatically kick in).
 
Does anyone else see this as a problem or is there some easy setting that I'm not aware of to
neutralize this issue?
 
-Norm
 
-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Norman J. Nolasco
Sent: Saturday, March 16, 2002 2:41 PM
To: [EMAIL PROTECTED]
Subject: RE: [IMail Forum] Old Hack on Hotmail seems to work on iMail web users...

Hi again,
 
I put up a new version of the email generator at http://209.16.59.28/test.asp
 
It can now send the same type of email to KillerWebMail users, as well as
default template users.  Again, even if the login screen doesn't use the same
template, all a malicious user has to do is cut&paste the HTML off the login
page onto their own version.
 
Norman Nolasco
Advarion Incorporated
 

Reply via email to