RE: XSS bug in hotmail login page

2002-10-08 Thread Thor Larholm
From: Russell Harding [mailto:[EMAIL PROTECTED]] Is there another way to exploit this which I am not seeing? Or does MSN actually have their act together (in this particular case...)? -Russell P.S. Well, I suppose the real question may be this: Is there a way to concatenate

Re: XSS bug in hotmail login page

2002-10-08 Thread Muhammad Faisal Rauf Danka
A lot can happen for sure, but i tried one myself, to redirect the request to some other webpage. One can make a fake hotmail page asking for password storing it locally in a text file and then again redirect to the original hotmail page. Usint this method one could steal passwords of

Re: XSS bug in hotmail login page

2002-10-08 Thread Berend-Jan Wever
:11 Subject: Re: XSS bug in hotmail login page A lot can happen for sure, but i tried one myself, to redirect the request to some other webpage. One can make a fake hotmail page asking for password storing it locally in a text file and then again redirect to the original hotmail page. Usint

RE: XSS bug in hotmail login page

2002-10-08 Thread Russell Harding
Hello, comments below: On Mon, 7 Oct 2002, Thor Larholm wrote: It's very simple, you can inject arbitrary scripting to be executed by the user in the context of hotmail. This means that you can e.g. steal his cookies or, if he's logged in, write emails from his account, delete his mails and

XSS bug in hotmail login page

2002-10-07 Thread Peter Rdam
Goodevening people, I've found a little (not sure) xss bug in the Hotmail login page, i just started to learn about xss bugs. I didnt tryd to much on this, i even contacted Microsoft. They prolly very busy with counting do, or its a harmless bug.. got no idea ;). They didnt reacted, and im