Yahoo Plugs Critical Security Hole in Web Mail Service

ADVERTISEMENTS

Yahoo Inc. said that it has fixed a critical security hole in its webmail service which could have allowed hackers to hijack users accounts. All the Yahoo mail users need not worry as they have to do nothing from their side.

We have developed a fix for this bug and have deployed it worldwide. Yahoo Mail users will not be required to take any action to be protected from this exploit,” said Kelley Podboy, a Yahoo spokeswoman, via e-mail.

The problem was Yahoo Mail’s handling of attachments. By creating an HTML attachment with different encoding schemes, one could have bypassed Yahoo Mail’s security filter and executed malicious JavaScript code, Bachar said via e-mail.

The problem was Yahoo Mail’s handling of attachments. By creating an HTML attachment with different encoding schemes, one could have bypassed Yahoo Mail’s security filter and executed malicious JavaScript code, Bachar said via e-mail.

It was also possible to steal the recipient’s Yahoo Mail cookie, hijack the session and gain access to the person’s in-box. “This attack vector could be used to launch a variety of other more sophisticated attacks,” Bachar wrote. These could include unleashing worms, installing keylogger programs, phishing, and scanning ports on the PC.

Via PCWorld

If you liked this article, click here to buy me a Beer! :)

If you enjoyed this post, make sure you subscribe to my RSS feed!

Related Entries


Leave a Reply