Hotmail, MSN and Amazon Susceptible to Attack via Cross Site Scripting

Softarea51.com is your source for all the latest computer technology and software related press releases.
Browse our archive for more press releases!

Released on: 5, July 2006
, Author: Tamara Borg / Acunetix
, Audience: Computers related

Recommended: Click here to improve PC speed »


London, UK Â 05 July, 2006 Â A 16 year old Dutch student,Adriaan Graas, interested in Internet security and web development discovered a hackfor the popular Hotmail free email service via a Cross Site Scripting attack.Microsoft, is reported to have been aware of this vulnerability for over a week but,at time of writing, has not yet fixed it.

Hacking hotmail via XSSWhen logging into Hotmail, a cookie is created allowing continual access of the userwhile within the domain. Hackers may steal such cookies and produce fakes using suchtools as Proxomitron. Since Hotmail cookies are not IP-bound, hackers do not needthe password or the email address of the victim for logging in and accessingpersonal emails and other data. Through Cross Site Scripting (XSS) the hackerinserts JavaScript code that will send the fake cookie to a Web Server with a logscript and the deed is done.

Vulnerabilities in MSN and Amazon left unfixedSecurity researcher, Yash Kadakia, frustrated by a lack of response from Microsoftand Amazon.com, has gone public with details of flaws on MSN and Amazon. Similar tothe Hotmail case, Cross Site Scripting and CRLF (Carriage Return Line Feed)injection vulnerabilities found in these sites could be used by hackers to steal"cookie" data files allowing them access to Amazon.com and MSN accounts, or todisplay a fake login page that could be used in phishing attacks.

Kadakia said he first notified Microsoft of the problem about a year ago but hewasn't taken seriously until late last week, when he posted screen shots of the flawbeing exploited on his Web site. The Amazon.com flaw was discovered in December andto-date the vulnerability remains un-patched, according to Kadakia.

Sanitizing Web ApplicationsAcunetix Web Vulnerability Scanner automatically audits web applications and checkswhether these applications are secure from exploitable vulnerabilities to such hackattacks as Cross Site Scripting and CRLF injection. An automated check of theHotmail, Amazon and MSN websites (using Acunetix WVS) could pinpoint these and anyother possible vulnerabilities before it is too late saving the popular companiesfrom undue embarrassment, loss of reputation and customer trust, and any financiallosses resulting from the attack.

Acunetix provides free audit to help companies determine the security of their websitesEnterprises who would like to have their website security checked can register for afree audit by visiting www.acunetix.com/security-audi t. Participating enterpriseswill receive a summary audit report showing whether their website is secure or not.Summary reports will be delivered within five business days of submission.

About Acunetix Web Vulnerability ScannerAcunetix Web Vulnerability Scanner ensures website security by automaticallychecking for SQL injection, Cross site scripting, CRLF injection and othervulnerabilities. It checks password strength on authentication pages andautomatically audits shopping carts, forms, dynamic content and other webapplications. As the scan is being completed, the software produces detailed reportsthat pinpoint where vulnerabilities exist.

About Acunetix Acunetix was founded to combat the alarming rise in web attacks. Its flagshipproduct, Acunetix Web Vulnerability Scanner, is the result of several years ofdevelopment by a team of highly experienced security developers. Acunetix is aprivately held company with headquarters based in Europe (Malta), a US office inSeattle, Washington and an office in London, UK. For more information aboutAcunetix, visit: http://www.acunetix.com; http://www.acunetix.de.

All product and company names herein may be trademarks of their respective owners.


Source: Express-Press-Release.com
Related downloads


Unique feature of FastScript is ability to use several languages (PascalScript, C++Script, JScript and BasicScript). FastScript doesn't use MS Scripting Host, so it can be used in Windows and Linux.

A cross-site lookup pack consists of SharePoint Cross-Site Lookup and SharePoint Cascaded Lookup extends SharePoint lookup function with new features. Powerful Cross-Site lookup other lists from different sites Filter filed values

Upload your web site to a FTP server, publish files on Amazon S3, or move or copy files that match a wildcard or regular expression with a single click.

FREE mail checker for FREE mail system - MAPInotify: Free HotMail Edition! is an advanced skinnable 32-bit HotMail-checker utility.

SharePoint cascaded lookup, cross-site lookup data in SharePoint list, filter SharePoint columns, convert between SharePoint lookup/cross-site lookup/cascaded lookup

The Prestwood Load Balancer is a cross-web server, cross-platform web request dispatcher that distributes direct HTTP calls to various web servers, based on the total number of pending requests to each server and the average response time.

Editize is a cross-browser, cross-platform rich text editor that can be easily integrated into any content management system. Since Editize isn't branded, you can make a profit by offering it to your web development clients.

DEKSI Net Remote is a .Net Cross platform and Cross device communications framework for PC's and PDA's. It allows you to build advanced systems with a basic networking knowledge.

MB Free Heart Attack Risk Calculator is a simple health software with an easy to use interface. The program is designed to calculate the risk of a person suffering from a heart attack in the next ten years depending on various factors.
Softarea51.com RSS Feed

Get RSS updates on latest computer technology and software related press releases Subscribe to Latest Press Releases RSS feed    Subscribe



You are welcome to include these headlines in your own pages. If you want to find out how to parse this RSS file please read our tutorial How to parse RSS feeds with PHP.