[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <Pine.NEB.4.53.0305072147570.29219@rhombus.znep.com>
From: marcs at znep.com (Marc Slemko)
Subject: Hotmail & Passport (.NET Accounts) Vulnerability
On Thu, 8 May 2003, Christopher F. Herot wrote:
>
> I just tried this. It does indeed generate the "reset password" email
> and link, which is scary, but following the instructions does not really
> reset the password, at least not for the limited test I performed.
It definitely worked for me around 20:45 (-0700).
Microsoft may have gotten it disabled by now, they do generally have
a very quick reaction time to such trivial stupid massive gaping holes
once they actually get the message about them.
Powered by blists - more mailing lists