Results 1 to 9 of 9

Thread: Hotmail & MSN Passport security...

  1. #1
    Ғо ѕніzzLє му піzzLє chicken's Avatar
    Join Date
    Nov 2005
    Location
    Kent
    Posts
    1,576
    Thanks
    28
    Thanked
    52 times in 43 posts

    Hotmail & MSN Passport security...

    I was just poking around Hotmail to attempt to find another way to log in for someone who was getting a blank screen and "done" instead of a login screen. One of the things I wanted to test was calling it up in another language just to see if it would work, so I took the "lc=1033" part out of one of the page addresses I had found and changed it to 1032, turning it arabic I think. I also changed the ID= number to find an alternative MSN Passport login site to Hotmail, and logged in there.

    On returning to Hotmail's login screen, my e-mail address was now in the username field and it only required a password to get to my mail. Instead of typing a password I added the lc=1033 line into the address bar to see if it worked, and to my surprise it logged me into my mail!

    So basically, if you leave a browser open that you've been logged into any MSN Passport site with, even if you have left that site another user could come along, go to Hotmail in it, type lc=1033 at the end of the address and read your mail. Luckily it seems closing the browser or pressing "Log Out" prevents access this way, but it still seems a bit unsecure to me, as you could probably access their entire passport like this.

    Always close your browser behind you!
    1.21 GIGAWATTS!!!!!

  2. #2
    Senior Member
    Join Date
    Apr 2005
    Location
    Bournemouth, Dorset
    Posts
    1,631
    Thanks
    13
    Thanked
    2 times in 2 posts
    Pressing Logout Deletes the Session ID so thats why it shouldnt let you see your emails when you press logout. I expect that hotmails Sessions are set to last quite a long time.

    if you left your self logged in for 10-15mins and then do what you did it shouldnt work i guess.

  3. #3
    Ғо ѕніzzLє му піzzLє chicken's Avatar
    Join Date
    Nov 2005
    Location
    Kent
    Posts
    1,576
    Thanks
    28
    Thanked
    52 times in 43 posts
    Hadn't touched it since writing that, it still works about 40 mins later.
    1.21 GIGAWATTS!!!!!

  4. #4
    Ғо ѕніzzLє му піzzLє chicken's Avatar
    Join Date
    Nov 2005
    Location
    Kent
    Posts
    1,576
    Thanks
    28
    Thanked
    52 times in 43 posts
    Hadn't touched it since writing that, it still works about 40 mins later.
    1.21 GIGAWATTS!!!!!

  5. #5
    Offline
    Join Date
    Jul 2003
    Location
    Oxford
    Posts
    418
    Thanks
    0
    Thanked
    0 times in 0 posts
    ... and we wonder why so many people manage to have their hotmail accounts 'stolen'!

  6. #6
    Senior Member
    Join Date
    Oct 2003
    Posts
    2,069
    Thanks
    4
    Thanked
    7 times in 3 posts
    Theyd o ave a logout button for a reason you know...
    Twigman

  7. #7
    Ғо ѕніzzLє му піzzLє chicken's Avatar
    Join Date
    Nov 2005
    Location
    Kent
    Posts
    1,576
    Thanks
    28
    Thanked
    52 times in 43 posts
    I know, but how often do you think people actually press it?

    It's not the fact that the session is still open that surprises me, but the fact you can get into it using just 7 characters that should have absoloutely nothing to do with verification. All that 1033 means is that it is to be displayed in English.

    Ah well, it was just a warning to people to log out/shut their browser upon leaving.
    1.21 GIGAWATTS!!!!!

  8. #8
    Senior Member
    Join Date
    Oct 2003
    Posts
    2,069
    Thanks
    4
    Thanked
    7 times in 3 posts
    Quote Originally Posted by chicken
    I know, but how often do you think people actually press it?
    I click logout everytime...doesnt everyone?
    Obviosuly there are some dumb people out there.
    Twigman

  9. #9
    smtkr
    Guest
    You certainly made it easier for me to login to my email at home. The only public terminals I use are in the lab and nothing from my current session remains after I log out (kind of annoying really--every time I come to the lab and use the web, I have a million 'you are exiting an encrypted page...check here if you don't want this displayed again' messages).

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. IEEE approves 802.11i security spec
    By Steve in forum PC Hardware and Components
    Replies: 1
    Last Post: 25-06-2004, 05:48 PM
  2. msn (lan related...i think) problems
    By Cesium in forum Networking and Broadband
    Replies: 4
    Last Post: 13-05-2004, 12:45 AM
  3. Have you done all of your windows updates ?
    By Moby-Dick in forum General Discussion
    Replies: 33
    Last Post: 05-05-2004, 01:23 PM
  4. Msn Hotmail Broken?
    By neonplanet40 in forum Networking and Broadband
    Replies: 5
    Last Post: 05-12-2003, 10:23 AM
  5. MSN problems
    By Mortal Wombat in forum Software
    Replies: 1
    Last Post: 08-10-2003, 10:16 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •