Another exploit (I'm not sure of whether or not M$ fixed it) is that if the user sets their hotmail to remember them at that computer, all it takes is for a cracker to copy two cookie files, and boom, they're in. Regardless of whwther or not the user changes their password.




