Yahoo email patch ineffective, security researchers say
- 10 January, 2013 01:45
- Comments
Security researchers say a patch released by Yahoo earlier this week for a serious email vulnerability did not fix the problem, leaving users at risk.
The cross-site scripting flaw was found by Shahin Ramezany, who goes by the nickname "Abysssec." The vulnerability can allow an attacker to harvest a victim's cookie for their Yahoo account if the victim is successfully tricked into clicking on a malicious link.
The vulnerability was patched by Yahoo on Monday, but penetration testing company Offensive Security and Ramezany say that the patch did not fix the problem.
"With little modification to the original proof-of-concept code written by Abysssec, it is still possible to exploit the original Yahoo vulnerability, allowing an attacker to completely take over a victim's account," Offensive Security wrote on its blog.
A Yahoo spokeswoman did not have an immediate comment when contacted Wednesday.
Offensive Security hosted a video showing how the attack works but left out details that might allow attackers to replicate it. The company said XSS filters provide little defense against an attack and warned that people should be wary of clicking on links within emails until Yahoo fixes the vulnerability.
Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk
- Bookmark this page
- Share this article
- Got more on this story? Email TechWorld
- Follow TechWorld on twitter
- Redbook - Scalable, Integrated Solutions for Elastic Caching Using IBM WebSphere eXtreme Scale
- Bloor Research - Why web security is best served in the cloud
- Revolutionary Security. Ultimate Performance. Minimal Management.
- Optimised Solution for E-Business Suite
- New Possibilities for Your Business with the World’s Fastest Database Machine
-
Philip's 'smart' lightbulbs hit Australia
-
Philip's 'smart' lightbulbs hit Australia
-
Bitcoin finding its feet at first Silicon Valley conference
-
Australia lags Mongolia in Internet speeds
-
Salesforce.com to buy Clipboard, shutting down service












Recent comments
2 hours, 14 minutes ago
4 hours, 50 minutes ago
18 hours, 38 minutes ago
5 days, 4 hours ago
6 days, 16 hours ago
6 days, 23 hours ago
1 week, 2 days ago
1 week, 3 days ago
1 week, 3 days ago
1 week, 4 days ago