Yahoo has fixed a potential security flaw in its email service that could have allowed hackers to hijack Yahoo email accounts
Security researchers alerted Yahoo to the the email flaw
R E L A T E D   C O N T E N T
ADVERTISEMENT

Yahoo fixes email hole

Malicious HTML attachment could reveal recipient's mail cookie

Andrew Charlesworth, vnunet.com 17 Aug 2006
ADVERTISEMENT

Yahoo has fixed a potential security flaw in its email service that could have allowed hackers to hijack Yahoo email accounts.

The problem was discovered earlier in August by Nir Goldshlager and Roni Bahar of Israeli security company Avnet

The security hole required hackers to create an HTML attachment with different encoding schemes to bypass Yahoo Mail's security filter and then execute JavaScript code to download the recipient's mail cookie.

Once acquired, the cookie would provide access to the email session and hence the email inbox to read, send and delete emails.

A recipient would have to open only the malicious email, not the attachment too.

Although the mail cookie would not have given the hacker password control over the email account directly, once the email session had been hijacked the hacker could have gained the password by using the facility offered by Yahoo (and all other mail providers) to email passwords to customers who have forgotten them.

After identifying the vulnerability, Bachar and Goldshlager immediately alerted Yahoo.

See also:

A new threat that could make BlackBerry devices vulnerable to attack requires "several reaching assumptions", according to Research In MotionBBProxy attack makes 'several reaching assumptions'  14 Aug 2006
Hacking program due to be released next week  09 Aug 2006
Online vandals have hacked the Netscape.com service using a cross-site scripting attackNetscape.com falls victim to cross-site scripting attack  27 Jul 2006
A Chinese company claims to have reverse-engineered the Skype protocol, allowing it to place calls over Skype's VoIP networkChinese firm finds a way into the network  14 Jul 2006
IT security experts warned today of a "widespread phishing email campaign" that tries to swindle unwary recipients by pretending to offer a cash prize from GmailNo such thing as a free lunch, warns security expert  11 Jul 2006
Hacking attacks on UK businesses are falling but the cost of security breaches is rising fastBig companies doing well, smaller ones less so  25 Apr 2006

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
The Role: 5 x Test Engineers The Duration: 3 months The Location: Wiltshire The Role 5 Test Engineers are required for contract positions working in the aerospace sector. The position will involve carrying out requirements ... more >
| Aston Carter
C# or C++ Front Office Analyst / Developer Interest Rate Derivatives £50,000 - £80,000 My Client a leading Investment Bank immediately requires a C++ Analyst / Developer to join a very successful IR Derivatives team. ... more >
| JAM Recruitment
Quality Assurance Documentation Clerk North West / Cumbria Contract – 3 months + The Role A Technical Clerk is required for a large defence organisation based in the North West. As the successful candidate you’ll ... more >
| JAM Recruitment
The Role: Systems Engineer The Location: Hampshire The Duration: 3 months The Role This vacancy exists for a Systems Engineer working for a large defence organisation. The position will involve producing Installation Guidance Packages, generating ... more >
More job opportunities