FYI…

- http://blog.washingtonpost.com/securityfix…ebmail_acc.html
August 2, 2007 - LAS VEGAS - "Logging into your MySpace, Facebook, Yahoo!, Gmail or Hotmail account over a wireless connection just got a lot more dicey, as researchers here at the Black Hat hacker conference today demonstrated a new set of tools that help automate the hijacking of those accounts… The attack works even if victims subsequently change their passwords, or actively sign out of their accounts. However, attackers would be unable to change the victim's password, as all of the above-named services force the user to reenter the current password before changing it to a new one. Gmail users who wish to log in to their accounts over a public Wi-Fi network can defeat this attack by taking advantage of a feature that encrypts all of the traffic between Google's servers and the browser (to do this, make sure you type https://gmail.google.com/ before providing your user name and password)…"

More URL's to defeat the hack:

Hotmail = https://login.live.com/login.srf?

Yahoo = https://login.yahoo.com/config/mail?

:ph34r: :ph34r: