ortep schrijft als eerste dat er weer een lek gevonden is in Hotmail, met een klein truukje is het mogelijk de inlog cookie te onderscheppen wat de mogelijkheid geeft om mailtjes te zenden en verwijderen zolang de echte gebruiker ook ingelogt is :
Since the cookie does not contain the user's password, the hacker can only access the account when the user is logged on and as long as the authentication code is valid. But Haselton said that five minutes would be long enough for a hacker with a prepared script to download all of a user's e-mail messages.
The trick uses JavaScript to send the cookie. Hotmail filters JavaScript in regular e-mail messages but doesn't filter JavaScript in HTML attachments.
"It's not a trivial bug that has to do with formatting; it's the essential nature of the software," Haselton said. "Hotmail is what all the big hunters set their sights on. ... Most of the free e-mail services can be broken into, and you find a new way to do it every three weeks or so. But it's really scary that hobbyists are the ones who are doing this."