Yahoo has fixed a potential security flaw
in its email service that could have allowed hackers to hijack Yahoo email
accounts.
The problem was discovered earlier in August by Nir Goldshlager and Roni
Bahar of Israeli security company
Avnet.
The security hole required hackers to create an HTML attachment with
different encoding schemes to bypass Yahoo Mail's security filter and then
execute JavaScript code to download the recipient's mail cookie.
Once acquired, the cookie would provide access to the email session and hence
the email inbox to read, send and delete emails.
A recipient would have to open only the malicious email, not the attachment
too.
Although the mail cookie would not have given the hacker password control
over the email account directly, once the email session had been hijacked the
hacker could have gained the password by using the facility offered by Yahoo
(and all other mail providers) to email passwords to customers who have
forgotten them.
After identifying the vulnerability, Bachar and Goldshlager immediately
alerted Yahoo.
The Role: 5 x Test Engineers The Duration: 3 months The Location: Wiltshire The Role 5 Test Engineers are required for contract positions working in the aerospace sector. The position will involve carrying out requirements ... more >
C# or C++ Front Office Analyst / Developer Interest Rate Derivatives £50,000 - £80,000 My Client a leading Investment Bank immediately requires a C++ Analyst / Developer to join a very successful IR Derivatives team. ... more >
Quality Assurance Documentation Clerk North West / Cumbria Contract – 3 months + The Role A Technical Clerk is required for a large defence organisation based in the North West. As the successful candidate you’ll ... more >
The Role: Systems Engineer The Location: Hampshire The Duration: 3 months The Role This vacancy exists for a Systems Engineer working for a large defence organisation. The position will involve producing Installation Guidance Packages, generating ... more >More job opportunities