Feeds

Malicious JavaScript shuts down Hotmail

Is there some reason why e-mail needs Java enabled?

  • alert
  • submit to reddit

Internet Security Threat Report 2014

Micro$oft's engineering bias preferring features over security has turned on them again. The company was forced to take its Hotmail service off line for about four hours Wednesday to bung a security hole enabling a malicious spammer to intercept Hotmail authentication cookies and take over users' accounts. The exploit uses an HTML attachment containing malicious JavaScript. When the victim views the attached file, the script intercepts the cookies and forwards them to a hostile site. The cookies are used for authentication and give anyone who intercepts them complete access to the victim's account, an intrusion which could also yield access to POP account passwords stored on the Hotmail server. Hotmail blocks JavaScript in e-mail messages, but not in attachments. Hotmail has fixed the hole by redirecting victims who activate the attachment before the JavaScript has a chance to intercept the cookies. Further details on the exploit and an example of the attachment are available from Peacefire. ®

Beginner's guide to SSL certificates

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Choosing a cloud hosting partner with confidence
Download Choosing a Cloud Hosting Provider with Confidence to learn more about cloud computing - the new opportunities and new security challenges.