http://www.2038.com/hotmail/
It's interesting that this exploit still works a number of hours after it became publically known. As a temporary workaround couldn't they just block accesses with www.2038.com in the referrer field?
John