November 5, 2001

MS Passport cracked with Hotmail

Author: JT Smith

The Register: "Passport and Wallet users are going to be disappointed to learn that these feature-rich tools can't be
used until MS fixes a little bug which makes sport of taking over someone else's account.

Passport authenticates a user for access to his credit cards and Web site accounts and passwords, to
make life easy for on-line merchants and shoppers, and hackers and identity thieves.

The flaw was discovered by Seattle researcher Marc Slemko, who devised a Hotmail exploit which
enables an attacker to use a malicious e-mail to obtain the victim's entire on-line shopping kit, and
take any action the owner can take."


  • Linux
Click Here!