Hacking at VSNL
|

|

|
|
VSNL Alert!:
Hacking at VSNL
Hacking the computer system by the use of cookies
by Raj Mehta, Bruce Gingery and Peter Doshi
Date: Sun, 25 Oct 1998 20:43:30 +0530
From: Elided <elided@elided.vsnl.net.in>
Reply-To: elided@elided.vsnl.net.in
Organization: this place designs
X-Mailer: Mozilla 4.03 (Macintosh; I; PPC)
MIME-Version: 1.0
To: "Dr. Raj Mehta"
Subject: Caution
If you receive a mail from Web Journalist do not
(repeat) go to VSNL Hacker Online. The guy hacks your
password. If you do do not allow him to set a cookie.
You will regret. Pass the message to all you know.
Elided
X-Mailer: Microsoft Outlook Express for Macintosh - 4.01 (297)
Date: Tue, 27 Oct 1998 21:34:08 +0530
Subject: Re: Caution
From: Elided <elided@elided.vsnl.net.in>
To: "Dr. Raj Mehta"
Hello Dr. Mehta,
Well it was not really difficult to see how the cookie made a
difference. First the location and the server were not mentioned in
the cookie file. As a matter of fact over a period of time I have
learnt to find out which cookie belongs to which server. Second thing
as I tried to change my password with VSNL, I could not. The cookie
file has a javascript as I figure it to be, and it prevents in some
way from changing to new password. After I deleted the cookie file
changing my password was a matter of few seconds. Thank you for
reminding me that I should not download files sent as attachments
unless I know the person sending it. Luckily I am on a Mac and not
many people are malicious or have the time to write programs that can
affect us but then again lots of my friends are on the PC and I don't
know how to help them. Probably VSNL at its end could stop mails that
are sent to addresses like alluser@bom5.vsnl.net.in. This should only
be the domain of VSNL. It might help in decreasing spam mail. There
are so many of the stuff just mailed across. Moreover it is a good
practice to subscribe only to those sites who do not sell the mail
addresses.
Hope our experiences can be shared with all the people in some format.
It is high time that we have Internet conferences held by IUCI and
VSNL or any ISP proposing to be to make people aware of such vicious
acts.
Will get back to you again.
Regards
Elided
|