Welcome, Guest. Please login or register.

Author Topic: Flaw exposes Microsoft ID service .net  (Read 4539 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline VincentTopic starter

  • Hero Member
  • *****
  • Join Date: Dec 2002
  • Posts: 3895
    • Show all replies
Flaw exposes Microsoft ID service .net
« on: May 10, 2003, 03:29:52 PM »
"Microsoft has admitted that for the last seven months up to 200 million Passport accounts have been vulnerable to plundering by thieves and malicious hackers.

The vulnerability lets a criminal get access to a Passport account using a specific web address and a trigger phrase.



Criminals exploiting the flaw could have gained access to personal information, credit card details and online mail accounts.

The Passport bug was found by Muhammad Faisal Rauf Danka, a freelance computer security consultant.

Some of the Passport accounts owned by Mr Danka and his friends had been hijacked.

In discovering how this was done, he found the website that gives privileged access to personal accounts and lets passwords be reset.

"It was so simple to do it. It shouldn't have been so simple," said Mr Danka, "Anyone could have done this."

Reportedly Mr Danka sent 10 messages to Microsoft detailing the vulnerability but got no response.

Microsoft only reacted when information about the flaw was posted online"

Full story:

BBC Technology Pages
Xbox360
"Oh no. Everytime you turn up something monumental and terrible happens.
I don\'t think I have the stomach for it." - Raziel
 

Offline VincentTopic starter

  • Hero Member
  • *****
  • Join Date: Dec 2002
  • Posts: 3895
    • Show all replies
Re: Flaw exposes Microsoft ID service .net
« Reply #1 on: May 10, 2003, 03:42:39 PM »
$11,000 per violation.  That's a hell of a lot of money even to m$.

btw, you might want to fix the link ;-)
Xbox360
"Oh no. Everytime you turn up something monumental and terrible happens.
I don\'t think I have the stomach for it." - Raziel
 

Offline VincentTopic starter

  • Hero Member
  • *****
  • Join Date: Dec 2002
  • Posts: 3895
    • Show all replies
Re: Flaw exposes Microsoft ID service .net
« Reply #2 on: May 10, 2003, 04:42:17 PM »
Quote
You'd think they would learn and not make the same mistakes.


You're hoping for a miracle there! :-P
Xbox360
"Oh no. Everytime you turn up something monumental and terrible happens.
I don\'t think I have the stomach for it." - Raziel