WHIR | BLOGS | WEB HOST NEWS | FIND WEB HOSTS | RESELLER HOSTING | MAGAZINE | WHIR TV | NEWSLETTER | rss feeds
web hosting news - daily web host interviews, insight Jobs | Events | Sitemap | Search
Green Data Center Info


WEB HOSTING NEWS | BLOGS | INTERVIEWS | EUROPE | EVENTS | WEB HOSTING JOBS

<< Mosso Offers New Hosting Cloud Tools     Equinix Houses Meebo Platform >>


Yahoo! Fixes Webmail Vulnerability

By Justin Lee, theWHIR.com

June 25, 2008 -- (WEB HOST INDUSTRY REVIEW) -- Search engine provider Yahoo! (yahoo.com) has patched a vulnerability that placed webmail users at risk of having their login information stolen, according to web application security firm Cenzic (cenzic.com).

   
DataPipe’s high-value managed global IT services help thousands of businesses decrease CAPEX, OPEX, & risk while increasing overall service levels. Partner with DataPipe – Improve your ROI - Extend your IT resources

The bug is a cross-site scripting flaw that left session IDs susceptible to theft during the interaction between Yahoo! mail and the Yahoo! Messenger instant messaging client.

Researchers at Cenzic found the flaw in May, and collaborated with Yahoo! in fixing the problem. Yahoo! says it fixed the bug on June 13, which was soon followed by Cenzic posting a detailed advisory on the issue.

The advisory describes that the hacker would have first had to add the proposed victim as a "buddy" before launching the attack. This would have only worked if the Yahoo! mail user had set up the Messenger support.

Cenzic writes: "If the attacker is using the Yahoo! Messenger desktop application 8.1.0.209 to chat with the victim, and the victim is using the Messenger support in the new Yahoo! Mail Web application, it will cause a new chat tab to open in the victim's browser. While chatting, the attacker can change their status to "invisible" causing a message of "offline" in the chat tab of the victim.

"The vulnerability occurred when the attacker then changed status, and sent a custom message containing a malicious string in the form of a status message of "online", with the script executed in the context of Yahoo! Mail on the victim's machine. This allowed an attacker to get active access to the victim's session ID, and in turn steal their Yahoo! identity, exposing sensitive personal information stored in their Yahoo! account."

The full Ceznic advisory can be viewed here.

Another security flaw was found in May in rival webmail service Google Gmail, which could enable spammers to use the free mail service as an open relay server.

In another setback to Yahoo!'s Webmail service, the company recently dropped security and anti-spam enhancements to the service after discovering the features prevented users from retrieving POP email from their external accounts.

Print this Page       Email this Page        Add to: | del.icio.us | digg


COMMENTS

Be the first one to comment on this article. Click the link below to post your comment.

[POST COMMENT]



Q&A: Jim Lewandowski, Rackspace

Q&A: Clint Poole, Brinkster

New Features in Parallels Plesk 9

Q&A: James Bond, Apptix

Noise Filter: McColo Taken Down

Wowza Offers Friction Free Flash

Sun Battles for Greenest Data Center

More feature interviews and reports
 

Go Daddy Ads in the Grey Cup

Video Interview with Vinay Nagpal, Tata Communications

Copywriting for Direct Mail - Part 2: Big Guns

What Exactly is Semi-Dedicated Hosting?

Own your own jet

MLB.com switches to Flash; Hosting and Video Streaming Questions

More posts from our Bloggers


NameCheap Launches Twitter Promo

CBS Web Site Faces Malware Hack

VineyardHosting Limits Eternal Hosting

Email Use Increases As Economy Slows

HostNine Re-Launches New Website

SoftLayer Sponsors MSDN Conference

Hosting Sales and Promos Roundup

SoftLayer Shows Continued Growth

Microsoft Named on Spam Host List

3FN Ups Hardware Swap Capability

ZNet Brings Hyper-V VPS to India

Black Friday Causes Shutdowns


 

Marketing/Sales Trainer

Sales Operator

Management Trainer

Senior Account Manager, Dedicated Hosting

Sales Executive

Senior Accounting Analyst

Technical Solutions Engineer

Product Manager

Account Manager

Ajax Experienced Developer

 

SPONSORED LINKS
> Apollo Hosting: Award Winning Website Hosting from $6.96 – Click Here!

> iWeb: Quality servers. 3000GB of traffic for only $69

> TopLayer: SC Mag Recommended. Protect against DDoS Attacks & more.

> Parallels: Automation and Virtualization. Buy ONLINE or Learn MORE!

> Rackspace: What Do You Get With Your Hosting Provider?

> Verio: Get Email Anywhere w/ Hosted Exchange $11.95/mo, 2 Mo Free

> IronScale: Why Rack? Automate with IronScale Managed Hosting

> Learn more about the greening of the data center here.

> Is your company hiring? Post your job listing here!

> Get your company listed in our annual Buyer's Guide magazine issue - Deadline: Dec 31

WHIR NEWSLETTER SIGN-UP | MANAGE SUBSCRIPTIONS | WHIR RSS FEEDS
Name:
Email:
Password:
theWHIR Blog Email Update
Magazine
Daily News
Find Web Hosts
Occupation:
Company Type:

Find Web Hosts | Reseller Hosting | Personal Web Hosting | Small Business Web Hosting | Dedicated Servers | Managed Hosting | Adult Web Hosting


About WHIR | Online Advertising | Print Advertising | Print Subscription | Email Newsletters | RSS Feeds
 
Submit News | Privacy Policy | Buy Reprints

Web Host Industry Review, Inc. is not responsible for the content of comments submitted by our users.

  © Copyright Web Host Industry Review, Inc.