Go Back   Windows Vista Forum | Vista Babble > Windows Vista > Vista News

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 06-21-2007, 04:11 AM
Snuffy's Avatar
Elite Members
 
Join Date: Nov 2006
Location: S.W. Kansas
Posts: 2,841
Snuffy is on a distinguished road
Send a message via MSN to Snuffy
Windows Live Bug Opened Door to Scammers


Windows Live Bug Opened Door to Scammers
Posted by Emil Protalinski on 19 June 2007 - 19:48 · There are 6 comments
Microsoft Corporation has fixed a bug in its Windows Live ID registration that let users deceptively register a false e-mail address. The false e-mail address could then be used as an ID for Microsoft's Live Messenger program, which could trick a user into thinking they are chatting with someone who is not whom they appear to be. Erik Duindam, a Web developer in Leiderdorp, the Netherlands, reported the problem to Microsoft on Monday. Microsoft acknowledged it had fixed the bug but did not have further information on the flaw's impact.

It's unclear how long the flaw may have existed or how many accounts with deceptive instant messenger IDs could have been created. If a user attempts to create a Windows Live ID, Microsoft sends a confirmation e-mail to the e-mail address entered by the user. Without confirmation, Microsoft includes a warning with future messages sent by instant message, which appear as: fake@emailaddress (E-mail Address Not Verified).

However, accounts created over the weekend with fake e-mail addresses were still active as of Tuesday and carried no such warning. Microsoft should try to shut down the fake accounts as soon as possible but it could be difficult, especially if Microsoft was not aware of the flaw and can't track the spoofed accounts. An attacker could use the flaw as part of a social-engineering ploy, where users are tricked into doing something that puts their machine at risk. Users could be tricked into thinking they are talking to someone they trust.

News source: PC World http://www.pcworld.com/article/id,13...1/article.html

__________________
The only Stupid Question is the one you failed to Ask!
Beta Tester since Pre Win 95.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 07:29 AM.



Page generated in 0.25701 seconds with 9 queries

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23