- Mythbuster busts his own tale
- 10 open source companies to watch
- Sony recalls 73,000 Vaio laptops
- Tool to evade China's Web censorship
- Chrome and Firefox and add-ons
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
Yahoo says it has fixed a vulnerability in Yahoo Mail that might have allowed savvy hackers to steal a victim's Yahoo identity and gain access to private information (Compare Data Leak Protection products).
Discovered by security vendor Cenzic last month, the underlying problem was a cross-site scripting (XSS) vulnerability that affected its current version of Yahoo Messenger and its new Yahoo Mail client Version 9, still in beta.
Cenzic vice president of marketing Mandeep Khera said the fix to the XSS vulnerability involves necessary changes in Yahoo servers, so users don’t have to download new Yahoo applications. “We don’t know how many users might have been exploited before this was fixed,” he said. “Potentially this was huge in terms of identity theft.”
“We are aware of the cross-site scripting vulnerability recently discovered in Yahoo Mail and we have completely resolved the issue as of June 13,” said Yahoo spokeswoman Kelley Podboy. “To our knowledge, the vulnerability was not exploited and users were not impacted. Yahoo takes user security very seriously as we continue our efforts to combat potential threats.”
Cenzic described how an attacker would have exploited the cross-site scripting vulnerability in Yahoo Mail prior to June 13. According to Cenzic, the attacker would be using the Yahoo Messenger desktop application 8.1.0.209 while chatting with the victim. The victim would need to be using the Messenger support in the new Yahoo Mail Web application.
A new chat tab would open in the victim’s browser. During the chat, the attacker could change their status to “invisible,” causing a message of “offline” in the chat tab of the victim. During this change of status, a savvy attacker could then send a custom message containing a malicious string in the form of a status message of “online,” with the script executed in the context of Yahoo Mail on the victim’s machine.
This would have allowed the attacker to get access to the victim’s session ID, and in turn steal their Yahoo identity, as well as exposing personal information stored in the Yahoo account.
“This vulnerability exposed millions of Yahoo users to the possibility of identity theft,” Khera pointed out.
Cenzic analysts alerted Yahoo to the findings of the cross-site scripting vulnerability last month, and Yahoo, which says it corrected the problem in June, is publicly disclosing the matter today.

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...
Vulnerability Management For DummiesDownload this concise book "Vulnerability Management for Dummies," to learn about the simple steps...
The ROI and TCO Benefits of Data Deduplication for Data Protection in the EnterpriseThis paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...
PoE Plus: Impact on the PoE MarketThe standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...
Harnessing the power of communications to increase workplace performanceDue to the convergence of IT and telecommunications technologies, the business workplace has been...

We have so many holes punched in our firewalls today that many industry insiders question the value...
The self-managed networkWe aren't there yet, but advances in network and systems management tools are making it possible to...
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comments (5)
Adobe InDesign CS3By Anonymous on June 29, 2008, 6:05 pmAdobe InDesign CS3
Reply | Read entire comment
The Article helps.By Anonymous on June 26, 2008, 6:29 amThis article helps a lot by actually explaining how the vulnerability can be exploited. We are living in an increasingly insecure world and getting more dependant...
Reply | Read entire comment
e mail off againBy Anonymous on June 26, 2008, 5:34 amI see that this morning all yahoo mail is not loading. Is this in anyway resolvable? Yahoo user
Reply | Read entire comment
Hope this is fixedBy Anonymous on June 25, 2008, 1:30 pmI hope the afore mentioned problem is now actually fixed.
Reply | Read entire comment
An important findBy Anonymous on June 25, 2008, 12:18 pmI am a regular yahoo user and these types of loopholes make my account all the more vulnerable. I hope there aren't any further findings like this in the yahoo...
Reply | Read entire comment
View all comments