Assata Shakur Speaks - Hands Off Assata - Let's Get Free - Revolutionary - Pan-Africanism - Black On Purpose - Liberation - Forum  

Assata Shakur Main Forum Portal Arcade Links/Downloads TTDC Search RBG Tube Warrior Chat Store Free Email Donate News
Go Back   Assata Shakur Speaks - Hands Off Assata - Let's Get Free - Revolutionary - Pan-Africanism - Black On Purpose - Liberation - Forum > Help, Suggestions And Security Center > P C Tech Advice & Technology
Forgot Password? Register

P C Tech Advice & Technology Post your PC related problems, share info related to the internet, test your avatars or images here.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-25-2008
Jahness's Avatar
OniOni Warrior
 
Join Date: Mar 2005
Location: In amerikkka! Stolen from Afrika!
Posts: 6,819
Thanks: 1,681
Thanked 1,112 Times in 695 Posts
Gender: Sister
Rep Power: 562
Jahness has a reputation beyond reputeJahness has a reputation beyond reputeJahness has a reputation beyond repute
Jahness has a reputation beyond reputeJahness has a reputation beyond reputeJahness has a reputation beyond reputeJahness has a reputation beyond repute
Arrow Yahoo fixes e-mail cross-site scripting flaw

Yahoo fixes e-mail cross-site scripting flaw

Yahoo fixes e-mail cross-site scripting flaw

Problem with the way Yahoo's Web mail interacted with its IM application could
allow a hacker to get access to a person's account



By Jeremy Kirk,
IDG News Service
June 25, 2008

Yahoo has fixed a vulnerability in its Web mail site that could allow a hacker to get access to a person's account.


The problem was in the way Yahoo's Web mail interacts with version 8.1.0.209 of its instant messaging (IM) desktop application, according to Web application security company Cenzic. Cenzic notified Yahoo of the problem in May.

If a hacker using the IM application starts chatting with a victim who is using the IM function of Yahoo's Web e-mail, a new chat tab is opened in the victim's Web browser. The attacker can then manipulate his presence status message to send a malicious script via IM. That script would then be executed in the context of Yahoo's e-mail service on the person's PC.

The script can reveal the victim's session ID to the attacker, who can then get access to information stored in that account, Cenzic said.

Cenzic classified the vulnerability as a cross-site scripting flaw, where scripts or commands from one Web application that shouldn't run in another are successfully executed. Security experts contend that cross-site scripting vulnerabilities are rampant on Web sites, posing dangerous risks to Web users.

Once in control of the account, the hacker could send spam. Yahoo and other free e-mail providers such as Microsoft have seen increasing use of their services for spam.

That's in part because the CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) security feature, which requires users to decode a jumble of distorted characters, has been increasingly defeated by machine-based processing.

The vulnerability would also allow access to a person's IM contacts. The hacker can then send instant messages purporting to be from a legitimate contact but with links leading to sites that try and exploit vulnerabilities in a person's Web browser or operating system.


Yahoo fixes e-mail cross-site scripting flaw | IDGNS | News | June 25, 2008 | By Jeremy Kirk, IDG News Service
__________________
Posted In The Spirit of Learning & Sharing
One Love & Respect Always

***************************************
The Quest for knowledge stops at the grave.
HIM Emperor Haile Selassie I.


If you fail to prepare,
you are preparing to fail!


Mind what you want, because someone wants your mind.

Working together, the ants ate the elephant.

Reply With Quote
Reply

Lower Navigation
Go Back   Assata Shakur Speaks - Hands Off Assata - Let's Get Free - Revolutionary - Pan-Africanism - Black On Purpose - Liberation - Forum > Help, Suggestions And Security Center > P C Tech Advice & Technology

Bookmarks

Tags
crosssite, email, fixes, flaw, scripting, yahoo


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Patches keep coming as Apple fixes OS X security bugs Jahness P C Tech Advice & Technology 0 02-12-2008 02:18 AM
Massive Java Update Includes Security Fixes Jahness P C Tech Advice & Technology 0 01-24-2008 02:48 AM
Yahoo says e-mail worm now contained Jahness P C Tech Advice & Technology 2 06-16-2006 01:49 AM
Yahoo Ordered to Share Reporter's E-Mail Jahness P C Tech Advice & Technology 0 09-10-2005 11:57 AM
T-mail will replace e-mail, says Philip Emeagwali Jacuma P C Tech Advice & Technology 7 03-20-2005 12:06 AM


New To Site? Need Help?

All times are GMT -4. The time now is 04:37 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2
The Talking Drum Collective
Page generated in 1.10464 seconds with 16 queries
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147