Follow Us

Yahoo plugs hole in web mail

Account access denied.

Yahoo has fixed a hole in its online email service that could have allowed hackers to gain access to accounts.

"We have developed a fix for this bug and deployed it worldwide," a company spokeswoman explained. The vulnerability itself was discovered by Israeli security company Avnet earlier this month and involves how Yahoo Mail handles attachments.

By creating an HTML attachment with different encoding schemes, one could have bypassed Yahoo Mail's security filter and executed malicious JavaScript code.

The exploit was such that the recipient only had to open the email without having to open the attachment itself. As a result, it was possible to steal an individual's Yahoo Mail cookie, hijack the session and gain access to the person's in-box.

"This attack vector could be used to launch a variety of other more sophisticated attacks," wrote Roni Bachar from Avnet. These could include unleashing worms, installing keylogger programs, phishing and scanning ports on the PC.

After identifying the vulnerability, Bachar and co-founder Nir Goldshlager immediately alerted Yahoo, so that the vendor could patch its system. Bachar isn't aware of any known exploits of the vulnerability.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *