Passport flaw leaves user info up for grabs

May 8, 2003, 07:46 AM —  IDG News Service — 

Microsoft Corp. has scrambled to shut down a flaw in its Passport service that could potentially reveal users' critical personal information, a company spokesman confirmed Thursday.

The flaw, which was reported to the company late Wednesday, was located in the service's password recovery system and would allow attackers to change an account password if they knew the user name.

Adam Sohn, a product manager with the Passport team, said Thursday that the flaw has been shut down and that the company is working to quickly fix the matter.

While Sohn said a preliminary investigation suggested that the vulnerability was not seriously exploited, it could potentially pose a large security threat to Passport users who store critical personal information such as credit card information with the service to access various online sites and services without having to retype information.

The vulnerability was in the function that allowed users to request a forgotten Passport password via e-mail. By tricking the system into initiating an e-mail password reset process, a malicious attacker could then request that the password be sent to a different e-mail address, Sohn said.

Microsoft has turned off this feature while it fixes the problem, and users requesting a forgotten password were instructed to use other means, such as going through the customer service support page.

Sohn said that the problem should be fixed "within hours" and that the company is actively investigating the matter.

IDG News Service

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Free stuff

Win an Amazon Kindle!
This month's giveaway gadget - Amazon's Kindle - will keep you entertained on the long trip home to visit family and friends over the holidays. Enter the drawing now!

Applied Security Visualization
By Raffael Marty
Published by Addison-Wesley Professional
Learn more!

 

IT Manager's Handbook
By Bill Holtsnider and Brian D. Jaffe
Published by Morgan Kaufmann
Learn more!

 

Windows Vista Resource Kit
By Mitch Tulloch, Tony Northrup, and Jerry Honeycutt
Published by Microsoft Press
Learn more!

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

More Resources