Hackers Shortcut Hotmail Password Reset Protections

S

s4

Guest
[QUOTEURL=http://www.newsbytes.com/news/02/174400.html]
Security researchers have discovered a vulnerability in Microsoft Corp.'s [NASDAQ: MSFT] Hotmail service that allows hackers to bypass security questions that users must answer before resetting their passwords.

Normally, if Hotmail users forget their password they must fill out a Web form that requires their e-mail address, state, zip code and country. Users who enter the correct information are then prompted for the answer to the "secret question" they selected when signing up for the service.
[/QUOTEURL]

The full story is longer than I like to copy and paste. Thought you'd like to know.
 
Top