Bitcoin Forum
May 07, 2024, 04:53:38 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Yahoo Flaw Allowed Hackers to Read Anyone's Emails  (Read 198 times)
TheIrishman (OP)
Legendary
*
Offline Offline

Activity: 1049
Merit: 1006


View Profile
December 09, 2016, 07:18:09 PM
 #1



Yahoo Flaw Allowed Hackers to Read Anyone's Emails

http://thehackernews.com/2016/12/hack-yahoo-email.html

<< Yahoo has patched a critical security vulnerability in its Mail service that could have allowed an attacker to spy on any Yahoo user's inbox.

Jouko Pynnönen, a Finnish Security researcher from security firm Klikki Oy, reported a DOM based persistent XSS (Cross-Site Scripting) in Yahoo mail, which if exploited, allows an attacker to send emails embedded with malicious code. In his blog post published today, the researcher demonstrated how a malicious attacker could have sent the victim's inbox to an external site, and created a virus that attached itself to all outgoing emails by secretly adding a malicious script to message signatures.

Since the malicious code is in the message's body, the code will get executed as soon as the victim opens the boobytrapped email and its hidden payload script will covertly submit victim's inbox content to an external website controlled by the attacker. >>
1715057618
Hero Member
*
Offline Offline

Posts: 1715057618

View Profile Personal Message (Offline)

Ignore
1715057618
Reply with quote  #2

1715057618
Report to moderator
1715057618
Hero Member
*
Offline Offline

Posts: 1715057618

View Profile Personal Message (Offline)

Ignore
1715057618
Reply with quote  #2

1715057618
Report to moderator
1715057618
Hero Member
*
Offline Offline

Posts: 1715057618

View Profile Personal Message (Offline)

Ignore
1715057618
Reply with quote  #2

1715057618
Report to moderator
The forum was founded in 2009 by Satoshi and Sirius. It replaced a SourceForge forum.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715057618
Hero Member
*
Offline Offline

Posts: 1715057618

View Profile Personal Message (Offline)

Ignore
1715057618
Reply with quote  #2

1715057618
Report to moderator
1715057618
Hero Member
*
Offline Offline

Posts: 1715057618

View Profile Personal Message (Offline)

Ignore
1715057618
Reply with quote  #2

1715057618
Report to moderator
1715057618
Hero Member
*
Offline Offline

Posts: 1715057618

View Profile Personal Message (Offline)

Ignore
1715057618
Reply with quote  #2

1715057618
Report to moderator
BitcoinBarrel
Legendary
*
Offline Offline

Activity: 1961
Merit: 1020


Fill Your Barrel with Bitcoins!


View Profile WWW
December 09, 2016, 07:51:39 PM
 #2

Just another reason why your personal information and data is never safe online or in a cloud. Even the largest companies are vulnerable.



        ▄▄▄▄▄▄▄▄▄▄
     ▄██████████████▄
   ▄█████████████████▌
  ▐███████████████████▌
 ▄█████████████████████▄
 ███████████████████████
▐███████████████████████
▐███████████████████████
▐███████████████████████
▐███████████████████████
 ██████████████████████▀
 ▀████████████████████▀
  ▀██████████████████
    ▀▀████████████▀▀
.
.....
.....
.....
.....
.....
.....





Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!