Microsoft says MSN flaw doesn't affect customers

Security hole could allow attacker to steal web users' account details

Written by Anthony Dhanendran, Computeract!ve

Microsoft has insisted that users of its MSN website should continue to use the site, despite a newly discovered security flaw.

Security researcher Yash Kadakia found that because of the way the technology behind the MSN site works, cookies issued by it could be stolen by hackers. These could then be used to gather information about legitimate users. The flaw also affects the Amazon shopping website, Mr Kadakia said.

The cookies mean a user only has to log in once to either their Amazon or My MSN site. Once logged in to the site, a user doesn't have to re-enter a password again to access their personal details.

Mr Kadakia found the flaw would allow hackers to produce fake cookies to impersonate a user, without having to have that user's password or email address. The hacker could then access the victim's account and emails.

Mr Kadakia says that he told Microsoft of the problem a year ago, but was ignored until he posted on his website screen captures of how the flaw could be exploited by a hacker.

A spokesperson for Microsoft said that it was aware of the vulnerability in its sites, and that it "will provide a solution to address the problem". Although the flaw has not yet been patched, the company says it is "not currently aware of any customer impact".

We are still waiting for comment about this flaw from Amazon.

Tags:

Reader comments

More from Computeractive

News

The latest home computing news

Downloads

The best PC tools, applications and more

Reviews

Independent opinions on new hardware and software

Step-by-step guides

Easy-to-follow projects with pictures

PC Help

Solve PC problems with our Q&A

Videos

PC projects demonstrated and product reviews

Articles

An in-depth look at how to get the best from your PC

Magazine

What's coming up in Computeractive

Forums

Get help with your PC problems from our readers

Competitions

Your chance to win computing prizes

Shopping

Great deals on products, services and more

Computeractive CD Rom 10
All 26 issues of Computeractive from 2007 on one CD-Rom.

Ultimate Guide to PC Troubleshooting
Everything you need to know to solve your PC problems.

Driving Test Success
The UK's best-selling driving test software.

Computeractive Back Issues
Missed an issue? Click here to find a back issue

Advertisement

Blogs

Windows Watch

Windows Watch

Keeping an eye on the latest XP and Vista news

More storage added to Windows Live Skydrive

19 Nov 2008The storage limit for Windows Live Skydrive is to be increased to a very respectable 25GB . As of just now my...

Download Junkie

Download Junkie

Your daily dose of download discussion

Tweak all areas of your display hardware

21 Nov 2008Most current graphics cards will come with a number of different display options. These settings are often pre-configured on any card installed...

Advertisement

Free email newsletters

Techno babble demystified...

[Display all definitions]

Or type in any computer-related word and click "Go"

Advertisement

Computeractive is not reponsible for content of Google adverts

Primary Navigation

© Incisive Media Ltd. 2008. Incisive Media Limited, Haymarket House,
28-29 Haymarket, London SW1Y 4RX, is a company registered in the United Kingdom with company registration number 04038503

Search computeractive.co.uk