Bugtraq mailing list archives
javascript hotmail password trap
From: david () KASEY UMKC EDU (David L. Nicol)
Date: Fri, 23 Apr 1999 13:55:24 -0500
Hello, I was informed this morning that a free form data mailer I maintain (http://www.tipjar.com/generic.html) was being involved in a javascript-based hotmail password stealing scheme. I have located the originating page (with the script) and sent it to the contact address hotmail puts on their autoresponder documents. I will share an URL for the (fully escaped) exploit in a week or two, to give hotmail time to patch their systems. (that's correct procedure, right?) So far the perp has a few dozen passwords (and I've got them too, they appear in my apache server log) I have offered to send hotmail the list. As there are many free form data mailers around, I am not making any modifications to my tool (which is performing correctly) which would chase the password trapper to another form mailer whose admin does not keep as good of logs. The page with the script on it contains a warning that your password has just been trapped; so unless there are other copies of this script running around all the victims know it already.
Current thread:
- Re: Shopping Carts exposing CC data Bo Elkjaer (Apr 23)
- javascript hotmail password trap David L. Nicol (Apr 23)
- Re: Shopping Carts exposing CC data Joe (Apr 23)
- Discus advisory. Elaich Of Hhp (Apr 23)
- Re: Discus advisory. Ian R. Justman (Apr 28)
- Re: Discus advisory. Elaich Of Hhp (Apr 29)
- X-based sniffer-netxmon Zhang Qianli (Apr 29)
- Re: X-based sniffer-netxmon route () RESENTMENT INFONEXUS COM (Apr 29)
- Re: X-based sniffer-netxmon Zhang Qianli (Apr 29)
- Buffer overflow in ftpd and locate bug Sergey V. Kolychev (Apr 30)
- Re: X-based sniffer-netxmon Corey Lindsly (Apr 29)
- Re: Discus advisory. Ian R. Justman (Apr 28)
- <Possible follow-ups>
- Re: Shopping Carts exposing CC data hevnsnt (Apr 23)