Skip to comments.
Hotmail, Yahoo Users at Risk of PC Takeover
Internet News ^
Posted on 03/23/2004 10:52:20 AM PST by Dbdaily
March 23, 2004 Hotmail, Yahoo Users at Risk of PC Takeover By Ryan Naraine
A potentially serious security flaw found in Web-based e-mail services offered by Microsoft (Quote, Chart) and Yahoo (Quote, Chart) could put millions of PCs at risk of takeover, an Internet security research firm warned Tuesday.
Israel-based security consultants GreyMagic issued the advisory with a chilling warning that attackers could inject malicious code by simply sending an e-mail to an unsuspecting Hotmail or Yahoo user.
The vulnerability only affects Hotmail and Yahoo running on Microsoft's Internet Explorer (IE) browser.
"When the victim attempts to read this email, the code executes and may result in severe consequences," the company said. Successful exploit could lead to theft of a user's login and password, disclosure of the content of any e-mail in the mailbox and disclosure of all contacts within the address book.
Additionally, GreyMagic said the attacker could manipulate the system to automatically send e-mails from the mailbox and to exploit vulnerabilities in IE to access the user's file system and eventually take over his or her machine.
The company said Microsoft reacted to its warning with a fix for the flaw. However, GreyMagic said all attempts to contact Yahoo's security department failed, meaning that Yahoo's users are still vulnerable. Efforts by internetnews.com to contact Yahoo at press time were unsuccessful.
GreyMagic said that many other Web-based e-mail services may be vulnerable to the flaw, since it is a completely new way to embed script.
The company released a proof-of-concept demonstration with its advisory, noting that the vulnerability makes use of an IE technology called HTML+TIME (based on SMIL), which is meant to add timing and media synchronization support to HTML pages.
One of the features of HTML+TIME is the ability to manipulate any attribute on an element via special control elements. For example, GreyMagic explained, the element exposes the attributes "attributeName" and "to", which make it possible to inject ANY HTML content to the document when "attributeName" is set to "innerHTML", and "to" is set to any HTML the attacker would like to execute, including script.
TOPICS: Business/Economy; Culture/Society; Miscellaneous; News/Current Events; Technical
KEYWORDS: computersecurity; greymagic; hotmail; ie; lowqualitycrap; maliciouscode; microsoft; opera; windows; yahoo
Navigation: use the links below to view more comments.
first 1-20, 21-40, 41-45 next last
1
posted on
03/23/2004 10:52:21 AM PST
by
Dbdaily
To: Dbdaily
And some people wonder why I use Opera...
2
posted on
03/23/2004 10:55:30 AM PST
by
ECM
To: Dbdaily
Hotmail is virus filtered by Mcafee before it gets to you. The filter will be always be as up-to-date as McAfee anti-virus.
3
posted on
03/23/2004 10:56:28 AM PST
by
js1138
To: Dbdaily
MSN email is also filtered, although they don't advertise it. I have received exactly zero viruses through MSN in the last year, but the virus filter log at work shows several per day. I have received emails through MSN along with a notice that an attachment has been deleted.
4
posted on
03/23/2004 11:00:28 AM PST
by
js1138
To: ECM
And some people wonder why I use Opera... That fat woman on TV?
5
posted on
03/23/2004 11:01:05 AM PST
by
MrB
To: Dbdaily
Interesting.
Yesterday I had an email in my Yahoo account which was suspicious. The sender claimed to be from Yahoo and it said that others had complained to Yahoo about spam being sent to them from my account. All of the options it gave me involved opening the attachment. One of the options was "add to address book."
6
posted on
03/23/2004 11:03:19 AM PST
by
pax_et_bonum
(Always finish what you st)
To: Dbdaily
Yahoo scans using Norton AV and tells you if something was detected which most of the time they remove. I never open emails from people I do not know. I just trash them.
7
posted on
03/23/2004 11:03:44 AM PST
by
hsmomx3
To: ECM
OSLO, Norway - Web surfers may be able to talk to their computers one day using a browser announced Tuesday by Opera Software.
PC of the Future
Get a preview of tomorrow's PC and desktop displays. Plus, where the PC won't be anytime soon.
The new browser incorporates IBM's ViaVoice technology, enabling the computer to ask what the user wants and "listen" to the request.
"Hi. I am your browser. What can I do for you?" asked a laptop with the demonstration versions of the browser.
The message can be personalized, such as greeting users by name. The computer learns to recognize users' voices, accents and inflections by having them read a list of words into a microphone.
Opera declined to give a launch date.
"Voice is the most natural and effective way we communicate," said Christen Krogh, head of Opera's software development. "In the years to come, it will greatly facilitate how we interact with technology.
8
posted on
03/23/2004 11:04:18 AM PST
by
BushCountry
(Eldest Boy's Funny T-Shirt Site (in college) -- http://www.cafeshops.com/lifeinamerica)
To: Dbdaily
To: pax_et_bonum
Definitely a scam - I got the same one on Sunday afternoon. It sounds almost official, doesn't it? Some grammatical error gave it away, though.
10
posted on
03/23/2004 11:05:13 AM PST
by
Xenalyte
("Marsa Stert is a britch and and I sit on the exhange")
To: ECM
Unfortunately, my version of opera (v6.03)is not accepted by hotmail. In other words, hotmail won't let me access my email using opera. Nice eh? Good thing I have yahoo..it'll take any browser so far.
11
posted on
03/23/2004 11:05:31 AM PST
by
Freedom2specul8
(Please pray for our troops.... http://anyservicemember.navy.mil/)
To: hsmomx3
I've gotten to the point where I don't open attachments from people I do know unless we plan it in advance. I've gotten a virus from a friend. :-p
12
posted on
03/23/2004 11:06:52 AM PST
by
Freedom2specul8
(Please pray for our troops.... http://anyservicemember.navy.mil/)
To: ECM

The only way to surf....
13
posted on
03/23/2004 11:08:27 AM PST
by
machman
To: js1138
Yahoo scans attachments with NAV. Just for the heck of it, I just checked my Yahoo account, and found three identical mails, all of them with infected attachments -
W32.Netsky.D@mm, to be precise. Anyway, Yahoo won't let you d/l dirty attachments, so I pretty much have to take their word for it.
14
posted on
03/23/2004 11:10:20 AM PST
by
general_re
(The doors to Heaven and Hell are adjacent and identical... - Nikos Kazantzakis)
To: Xenalyte
Yes, the grammatical errors were red flags. The sender must be a liberal.
:-)
Also, even though I'm not the most computer literate person around, I thought it was suspicious 1) that there was a need for me to open an attachment, considering the supposed "problem" and 2) that the Yahoo complaint department would want to be added to my address book.
15
posted on
03/23/2004 11:12:02 AM PST
by
pax_et_bonum
(Always finish what you st)
To: general_re
I find that the amount of spam I'm receiving in hotmail and MSN has dropped 90% in the last few months. I used to set aside a half hour each week to forward spams to the abuse@ people. I suspect they've learned some good ways to detect spoofed return addresses and relayed messages.
Centralized filtering and lawsuits are the only way this can be managed.
16
posted on
03/23/2004 11:21:02 AM PST
by
js1138
To: js1138
Actually, both Yahoo! Mail and the email from my ISP (EarthLink/MindSpring) use Norton Antivirus on the mail server version so the viruses are caught and stamped out before you can download them. In short, I don't get to see dangerous mail attachments on my local computer. =)
To: Dbdaily
Yawn!
18
posted on
03/23/2004 11:25:15 AM PST
by
sully777
(Our descendants will be enslaved by political expediency and expenditure)
To: RayChuang88
I suppose they don't advertise this much because they don't want to be liable if they let a killer virus through, but I'm sure the transmission of viruses is going down. Just in the last few months. I got hit real hard 18 months ago, and haven't seen any since (Now that I have NAV installed, it doesn't have anything to do.)
19
posted on
03/23/2004 11:30:52 AM PST
by
js1138
To: MrB
That fat woman on TV?
You're confused....you're thinking of Okra.
20
posted on
03/23/2004 11:36:39 AM PST
by
ErnBatavia
(Gay marriage is for suckers...)
Navigation: use the links below to view more comments.
first 1-20, 21-40, 41-45 next last
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson