have tested the code included in Georgi's email an it seems that Yahoo's web-based
email is also vulnerable.
solutions: disable JS
Kevin Hecht <khecht19 IDT NET> wrote:
Georgi Guninski wrote:
>
> Georgi Guninski security advisory #1, 2000
>
> Hotmail security hole - injecting JavaScript using > LOWSRC="javascript:....">
>
> Disclaimer:
> The opinions expressed in this advisory and program are my own and not
> of any company.
> The usual standard disclaimer applies, especially the fact that Georgi
> Guninski is not liable for any damages caused by direct or indirect use
> of the information or functionality provided by this program.
> Georgi Guninski, bears NO responsibility for content or misuse of this
> program or any derivatives thereof.
>
> Description:
> Hotmail allows executing JavaScript code in email messages using > LOWSRC="javascript:....">,
> which may compromise user's Hotmail mailbox.
>
> Details:
> There is a major security flaw in Hotmail which allows injecting and
> executing JavaScript code in an email message using the javascript
> protocol. This exploit works both on Internet Explorer 5.x (almost sure
> IE 4.x) and Netscape Communicator 4.x.
> Hotmail filters the "javascript:" protocol for security reasons.
> But the following JavaScript is executed: > LOWSRC="javascript:alert('Javascript
is executed')"> if the user has
> enabled automatically loading of images (most users have).
>
> Executing JavaScript when the user opens Hotmail email message allows
> for example displaying a fake login screen where the user enters his
> password which is then stolen.
> I don't want to make a scary demonstration, but it is also possible to
> read user's messages, to send messages from user's name and doing other
> mischief.
> It is also possible to get the cookie from Hotmail, which is dangerous.
> Hotmail deliberately escapes all JavaScript (it can escape) to prevent
> such attacks, but obviously there are holes.
> It is much easier to exploit this vulnerability if the user uses
> Internet Explorer 5.x
www.securityfocus.com