Cross-site scripting attack on Hotmail highlights personal e-mail risk to business

News

Cross-site scripting attack on Hotmail highlights personal e-mail risk to business

Warwick Ashford

A vulnerability in the Hotmail site has enabled hackers to steal an unknown number of messages from users' accounts, according to security firm Trend Micro.

The attack highlight the underrated and often-ignored risk of allowing employees to check their personal e-mail accounts at work, the company says.

Cross-site scripting (XSS) is a common security vulnerability in web applications that enables attackers to inject client-side script into web pages viewed by other users, but rarely found in prominent sites such as Hotmail.

The vulnerability enabled hackers to display a message that looked like a Facebook notification warning the victim's account had been accessed from a new location. Embedded in the message was a script that forwarded the victim's e-mail messages to the hackers.

The attack would launch if the victim was logged into Hotmail and either read or previewed the booby-trapped fake Facebook warning message.

"The script triggers a request that is sent to the Hotmail server. The said request sends all of the affected user's e-mail messages to a certain e-mail address," Trend Micro said in a blog post.

The attack exploits a script or a CSS filtering mechanism bug in Hotmail (CVE-2011-1252), which Microsoft has fixed in an update to Hotmail.


Email Alerts

Register now to receive ComputerWeekly.com IT-related news, guides and more, delivered to your inbox.
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
 

COMMENTS powered by Disqus  //  Commenting policy