home |  
Sell Downloads - Ejunkie
open db network by 19.5 degrees
LYRICS | FREE E-BOOKS | SELL DOWNLOADS WITH PAYPAL
 in   
 
contribute for fun & profit
brink
-Bug in Rediffma..
-E-commerce / Se..
-New Media Artic..
-Technology Arti..
 
See all Computers and Internet Articles
 
-Art Articles..
-Astrology Tutor..
-Beauty Articles..
-Body / Mind / S..
-Business / Econ..
-Computers and I..
-Education Artic..
-Family / Relati..
-Feng Shui Artic..
-Food and Bevera..
 
See all Articles, Information and Tips
 
articles
All Resources > Articles, Information and Tips > Computers and Internet Articles > INTERNET ARTICLES
spread the word around  send this page to a friend   read/write comments/corrections/additions comments  rate this 

Bug in Rediffmail

by 19.5 Degrees
 
 
views: 38708 | rating: 4/10
 


DISCLAIMER:

I really do not understand why I have been recieving a lot of requests for hacking rediffmail. This article is NOT intended to help anybody hack rediffmail (india based free online email service) or any other email service. I personally appreciate these free email services and I think they are doing a great job. The sole purpose of this article is to bring this vulnerability/bug in notice of concerned authorities as my email to feedback@rediff.co.in and newhome@rediffmail.com (Sent: Monday, October 28, 2002 8:36 AM Subject: Bug in rediffmail) has remained un-answered till date.

BUG:
Bug lies in rediffmail.com not stripping out JavaScript code hidden in <img> tags. If a mail with hidden JavaScript redirection code is sent to user, he can be redirected to a page sender wants. As soon as the user clicks to read the mail, he would be redirected to the page the sender wants even before the mail content is shown. The redirection happens in the same window and the unsuspecting user would not have slightest idea that he is now at a page that does not belong to rediffmail.com unless he looks at the URL bar of his browser.

CONSEQUENCES:

1. This new page where the user will get redirected to can be a duplicate of the login screen and user can loose his or her password to anyone. It is very easy to trick someone using the common "session expired, you need to login again" error to make a user enter his password again.
2. If this new page again redirects the user to a malformed .eml file, Any executable that the sender has encoded in the .eml file (Base64 encode) would execute on the user's machine(on unpatched IE 5.5). And this can cause havoc, this can be a virus or code to format user's hard drive or a trojan or something like Back Orifice or ANYTHING. So user would be totally at the mercy of the sender now. Though this bug is in Internet Explorer but the user can fall pray to it because he was using the particular email service.

EXPLOIT:


The exploit can be a simple HTML email that has to be sent to the target email account. This HTML email can be formed using source edit in outlook express or using any scripting language.

<HTML>
<HEAD></HEAD>
<BODY bgColor=#ffffff>
<IMG src="java-script:window.location='http://www.any.domain.com/any.page.htm'>
<DIV><FONT face=Arial size=3>hi, you would be redirected even before you get a chance to read this text</FONT></DIV>
</BODY>
</HTML>


FIX:

Rediffmail.com should parse each email to replace each occurrence of "java-script" in the email message with "java-script".

« PREVIOUS
  INDEX
NEXT »

spread the word around
read comments

hiii
posted by: kapil kalra
on: Nov 21, 08 2:38 am

I have forget my id password of mail id kapilkalra99@rediffmail.com.... i am not able to login can you send me the password on my mail id indurana5@yahoo.co.in

waiting for your reply

kapil kalra

post reply | read replies (1)



forget my rediff id's password
posted by: jayasri
on: Apr 14, 06 2:44 am

sir i forget my rediff id's password pls help me

and that id is avcdts@rediffmail.com

post reply | read replies (260)



forget password
posted by: gaurav
on: Nov 21, 08 8:59 am

hello sir

i'm forget my rediff account password .pls tell me how can i open my id

post reply | read replies (0)



Please help me
posted by: Praneet
on: Oct 17, 08 6:08 am

I want to Hack the password of rediffmail account, which belongs to my Girlfriend, I am Confirmed that she is flerting with me.
If some one can give me her account password, please reply me at Praneet1103@rediffmail.com I want to comunicate with you pesonally. Please

post reply | read replies (0)



Crack Hotmail & MSN, Crack Yahoo, Crack AOL
posted by: Joline Bellemare
on: Oct 7, 08 6:33 am

FASTEST GENUINE RELIABLE AND CONFIDENTIAL PASSWORD SERVICE

Email address: hack-email-passwords@milanorosa.com


If you are looking for a Genuine, fast, reliable and confidential email cracking service then visit
http://www.milanorosa.info



http://www.milanorosa.biz



http://www.milanorosa.us


Don't get befooled by the scam making peoples on net.
Milanorosa is run by well known experts. We take yours request seriously and execute fastest.

Our charges are nominal that you can pay only after yours job is done and if you are satisfied.

Make a request now - go to any of these website listed below:
http://www.milanorosa.info



http://www.milanorosa.biz



http://www.milanorosa.us



• We reserve the right to acquire more information if necessary and refuse service if the info you give to us is incorrect.
• Our charges is only 150USD / 1 cracking session
• You can send money using any of these listed below method of payment
- PayPal
- Western Union
- MoneyGram
- MoneyBookers

Only 5 Steps to get cracked your target password
1. Submit the target id to hack-email-passwords@milanorosa.com


2. After Successful Crack we will send you the proofs (Usually in 2-3 days maximum)
3. Verify proofs and if you are well satisfied then you can reply back.
4. We will send the detailed payment information after getting reply.
5. After payment confirmation we will send the original password currently used by your "target"

You can send a request via email to hack-email-passwords@milanorosa.com with the following content:

1. Target Email
2. Target Name
3. Your Name:
4. Your Country:
5. Reason why you need this kind of service
6. Your preffered method of payment (paypal, westernunion, moneygram or moneybookers):

You don`t have to pay anything in advance, the payment is expected only after a successfull cracking process and you are convienced that we have access at target`s account.
To proof that we have got the password, we will send you some screenshots from target`s account (inbox folder, sent items, contacts, account information page etc ).
The password we provide is the original one or in another words it is the current password that the victim is using.
We do not change the password like others competitors and we do not try to guess the answer at secret question.
The victim will not realise that he/she has been hacked since your victim will share with you the same password here is 100% discret service.

Email:
hack-email-passwords@milanorosa.com

Website:
http://www.milanorosa.info



http://www.milanorosa.biz



http://www.milanorosa.us


KEYWORDS : hack, hacking, crack, cracking, yahoo, aol, hotmail, email, password passwords, account,exite hacking,yahoo hacking,hotmail hacking,lovemail hacking,sify hacking,reddiff hacking,account hacking,hire hackers,rent hackers,rent a hacker,pay hackers,money hacking,money cracking,crack on cash,hack on cash,hacking tools,trojans,keyloggers,hacking prodcuts,underground store,money hacking,password revovery,revovering ur password,passwordreminders,pass,pwd,passwordz,cracks,crackers,sabotage,social enginerring,website hacking,website cracking,databse debugging,database stealers,database hacking,db hack,stealing privacy,Computer Hacking, Steal of any Secret Document from any computer,Spy on any computer or any secret info needed.,Any file password cracking like Ms-word or Zipfiles,Virus / Worm Programming like Keylogger or Trojans,Software Source Code,zip caracking,word craking,softwatre hacking, hack yahoo, hack gmail, hack hotmail, hack msn, crack yahoo, crack gmail, crack hotmail, crack msn, hack aol, crack aol, hacking yahoo, hacking hotmail, hacking msn, hacking aol, cracking aol, cracking msn, cracking yahoo, cracking hotmail, hacking email, hack email, hack password, hack passwords, hacking passwords, cracking password, cracking passwords, email password hacking, hacking hotmail passwords, password hacking, hacking passwords, password hacking programs, crack yahoo, learn how to hack, email password cracking, hack yahoo passwords, hack passwords, hack hotmail, email hacking, hack email, crack hotmail, hacking tools, hotmail hacking, email passwords hacking, yahoo mail hack

post reply | read replies (2)



read more commentsread more comments   |   read more commentspost comment 



home | contact | contribute | terms of use | privacy policy |