Welcome, Guest. Please login or register.

Author Topic: Flaw exposes Microsoft ID service .net  (Read 4511 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline VincentTopic starter

  • Hero Member
  • *****
  • Join Date: Dec 2002
  • Posts: 3895
    • Show only replies by Vincent
Flaw exposes Microsoft ID service .net
« on: May 10, 2003, 03:29:52 PM »
"Microsoft has admitted that for the last seven months up to 200 million Passport accounts have been vulnerable to plundering by thieves and malicious hackers.

The vulnerability lets a criminal get access to a Passport account using a specific web address and a trigger phrase.



Criminals exploiting the flaw could have gained access to personal information, credit card details and online mail accounts.

The Passport bug was found by Muhammad Faisal Rauf Danka, a freelance computer security consultant.

Some of the Passport accounts owned by Mr Danka and his friends had been hijacked.

In discovering how this was done, he found the website that gives privileged access to personal accounts and lets passwords be reset.

"It was so simple to do it. It shouldn't have been so simple," said Mr Danka, "Anyone could have done this."

Reportedly Mr Danka sent 10 messages to Microsoft detailing the vulnerability but got no response.

Microsoft only reacted when information about the flaw was posted online"

Full story:

BBC Technology Pages
Xbox360
"Oh no. Everytime you turn up something monumental and terrible happens.
I don\'t think I have the stomach for it." - Raziel
 

Offline The_Editor

  • Hero Member
  • *****
  • Join Date: Feb 2002
  • Posts: 1863
    • Show only replies by The_Editor
Re: Flaw exposes Microsoft ID service .net
« Reply #1 on: May 10, 2003, 03:34:23 PM »
And according to "The Reg", M$ has been fined 2 TRILLION Dollars!!

Yeah Right !!

The Reg
The Reluctant Pom
 

Offline VincentTopic starter

  • Hero Member
  • *****
  • Join Date: Dec 2002
  • Posts: 3895
    • Show only replies by Vincent
Re: Flaw exposes Microsoft ID service .net
« Reply #2 on: May 10, 2003, 03:42:39 PM »
$11,000 per violation.  That's a hell of a lot of money even to m$.

btw, you might want to fix the link ;-)
Xbox360
"Oh no. Everytime you turn up something monumental and terrible happens.
I don\'t think I have the stomach for it." - Raziel
 

Offline JoannaK

  • Hero Member
  • *****
  • Join Date: Dec 2002
  • Posts: 757
    • Show only replies by JoannaK
Re: Flaw exposes Microsoft ID service .net
« Reply #3 on: May 10, 2003, 03:45:44 PM »
Could be fined... Has not happened Yet .  IMHO should happen,  but most likely not.  :-(
 

Offline Paul_Gadd

  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 1271
    • Show only replies by Paul_Gadd
    • http://elunatic.host.sk/start.html
Re: Flaw exposes Microsoft ID service .net
« Reply #4 on: May 10, 2003, 03:52:07 PM »
Quote
Microsoft said it had locked all compromised accounts and fixed the bug.


To late the damage has been done and you deserve all you get.
 

Offline SidMan

  • Jr. Member
  • **
  • Join Date: Sep 2002
  • Posts: 88
    • Show only replies by SidMan
Re: Flaw exposes Microsoft ID service .net
« Reply #5 on: May 10, 2003, 04:03:21 PM »
Paul,

Not even Mr Sheen can wipe away this damage! eh!  :-D

SidMan.
 

Offline Argo

  • Hero Member
  • *****
  • Join Date: Feb 2002
  • Posts: 3219
    • Show only replies by Argo
Re: Flaw exposes Microsoft ID service .net
« Reply #6 on: May 10, 2003, 04:28:00 PM »
Hey, This is just like the Hotmail security hole that was in the news a year or so ago. You'd think they would learn and not make the same mistakes.
 

Offline VincentTopic starter

  • Hero Member
  • *****
  • Join Date: Dec 2002
  • Posts: 3895
    • Show only replies by Vincent
Re: Flaw exposes Microsoft ID service .net
« Reply #7 on: May 10, 2003, 04:42:17 PM »
Quote
You'd think they would learn and not make the same mistakes.


You're hoping for a miracle there! :-P
Xbox360
"Oh no. Everytime you turn up something monumental and terrible happens.
I don\'t think I have the stomach for it." - Raziel
 

Offline elendil

  • Sr. Member
  • ****
  • Join Date: Nov 2002
  • Posts: 324
    • Show only replies by elendil
    • http://www.idiot.fnuck.dk
Re: Flaw exposes Microsoft ID service .net
« Reply #8 on: May 10, 2003, 05:28:35 PM »
Argo:

That avater is simply outstanding!

Sincerely,

-Kenneth Straarup.
 

Offline Paul_Gadd

  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 1271
    • Show only replies by Paul_Gadd
    • http://elunatic.host.sk/start.html
Re: Flaw exposes Microsoft ID service .net
« Reply #9 on: May 10, 2003, 06:27:11 PM »
@SidMan

Mr Sheen is only for the good guys, bad guys go without.  :lol:
 

Offline Snuden

  • Jr. Member
  • **
  • Join Date: Mar 2002
  • Posts: 50
    • Show only replies by Snuden
    • http://lightworkings.dk
Re: Flaw exposes Microsoft ID service .net
« Reply #10 on: May 10, 2003, 06:30:20 PM »
Quote
Hey, This is just like the Hotmail security hole that was in the news a year or so ago. You'd think they would learn and not make the same mistakes.


Learn? IMHO they just don't care.

Kind Regards
Kind Regards

Morten Strårup

If you do things right, people won\\\'t be sure if you\\\'ve done anything at all.
 

Offline Quixote

  • Hero Member
  • *****
  • Join Date: Mar 2002
  • Posts: 2059
    • Show only replies by Quixote
Re: Flaw exposes Microsoft ID service .net
« Reply #11 on: May 10, 2003, 08:43:00 PM »
Vincent voiced:
Quote
$11,000 per violation. That's a hell of a lot of money even to m$.
;-) It is supposedly $11,000 for each customer.  How much do you want to bet the customer never sees it, even if Microsoft pays up?
 

Offline cap

  • Newbie
  • *
  • Join Date: Feb 2002
  • Posts: 44
    • Show only replies by cap
Re: Flaw exposes Microsoft ID service .net
« Reply #12 on: May 11, 2003, 12:40:46 AM »
I'm dying,perhaps its too much alcohol,l>?~o>?~l>?~ at the avatar!"argo"

I'm a big fan of the X-Files.
A500+ A530 40mhz Action Replay
A1200 Blizzard 060/233 grex voodoo 3000
A1 G4/1ghz Radeon 9250
 

Offline toRus

  • Full Member
  • ***
  • Join Date: Mar 2003
  • Posts: 122
    • Show only replies by toRus
Re: Flaw exposes Microsoft ID service .net
« Reply #13 on: May 11, 2003, 12:43:33 AM »
Some people never learn. Would you buy a firewall program developed by Micro$oft ?
 

Offline Waccoon

  • Hero Member
  • *****
  • Join Date: Apr 2002
  • Posts: 1057
    • Show only replies by Waccoon
Re: Flaw exposes Microsoft ID service .net
« Reply #14 on: May 11, 2003, 01:44:53 AM »
Quote
Snuden:  Learn? IMHO they just don't care.

They're not mistakes. -- they're sales points.  If people tolerate it, anything is OK.

Really, I blame the public.  If they refused to use all this crap things would be much better.  I refuse to buy WinXP.  Period.

My biggest gripe with Passport is that it is constantly in your face.  Install WindowsXP, and it just pops out at you.  There's no way to turn it off.  Even if you get the icon to disappear from the taskbar, it's still running in the background.

The ultimate solution:  Use Windows2000 and don't download security updates.  Security updates just turn on all kinds of stupid features because now Microsoft verifies that they are "fixed".  I'm re-installing Win2000 and downgrading to IE5.5 because I've had so many security and reliability problems with IE6, never mind Passport!