Cross-site scripting attack on Hotmail highlights personal e-mail risk to business


Cross-site scripting attack on Hotmail highlights personal e-mail risk to business

Warwick Ashford

A vulnerability in the Hotmail site has enabled hackers to steal an unknown number of messages from users' accounts, according to security firm Trend Micro.

The attack highlight the underrated and often-ignored risk of allowing employees to check their personal e-mail accounts at work, the company says.

Cross-site scripting (XSS) is a common security vulnerability in web applications that enables attackers to inject client-side script into web pages viewed by other users, but rarely found in prominent sites such as Hotmail.

The vulnerability enabled hackers to display a message that looked like a Facebook notification warning the victim's account had been accessed from a new location. Embedded in the message was a script that forwarded the victim's e-mail messages to the hackers.

The attack would launch if the victim was logged into Hotmail and either read or previewed the booby-trapped fake Facebook warning message.

"The script triggers a request that is sent to the Hotmail server. The said request sends all of the affected user's e-mail messages to a certain e-mail address," Trend Micro said in a blog post.

The attack exploits a script or a CSS filtering mechanism bug in Hotmail (CVE-2011-1252), which Microsoft has fixed in an update to Hotmail.

Email Alerts

Register now to receive IT-related news, guides and more, delivered to your inbox.
By submitting your personal information, you agree to receive emails regarding relevant products and special offers from TechTarget and its partners. You also agree that your personal information may be transferred and processed in the United States, and that you have read and agree to the Terms of Use and the Privacy Policy.

COMMENTS powered by Disqus  //  Commenting policy