Donate Now Goal amount for this year: 799 USD, Received: 100 USD (13%)
Please donate to help support this website. The funds will be used to purchase owned license of LiteSpeed Web Server Enterprise (2-CPU). It provides superior performance in terms of raw speed, scalability and anti-DDoS capabilities.

Results 1 to 2 of 2
  1. #1
    Verified Member
    Points: 15,481, Level: 80
    Level completed: 27%, Points required for next Level: 369
    Overall activity: 0.4%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Jun 2008
    Location
    Sri Lanka
    Posts
    2,072
    Liked
    1 times

    Phishing Attack Uses Yahoo HotJobs XSS Vulnerability



    Netcraft, a British company that offers Internet and security services, announced that a phishing attack was compromising Yahoo accounts. According to the company, the attack was using obfuscated JavaScript code injected in the hotjobs.yahoo.com website in order to gather authentication cookies from users accessing the page. Yahoo was notified and fixed the problem.

    The attackers used a cross-site scripting vulnerability in the Yahoo! HotJobs website in order to inject malicious obfuscated JavaScript code into the page. The JavaScript code was used to pass the authentication cookies sent by the browsers to another external website set up by the attackers in the US. Using the stolen cookies, the attackers hijacked the user sessions and gained access to all Yahoo services that required authentication.

    An authentication cookie is a text file served by the web server to the user's browser after a successful login. The file allows the web server to keep the session opened for a period of time or until the user logs out. When trying to access a resource that requires authentication, the web server asks the browser for this cookie file. If the file exists and the browser is able to return it, the web server allows access to the resource.

    According to Netcraft, enforcing HTTP-only cookies, which are supported by all modern browsers, would have mitigated this attack, since cookies tagged with this attribute cannot be accessed by server-side scripts. The company also points out that a highly similar attack using Yahoo compromised pages was detected earlier this year.

    “In both cases, Netcraft found that the Yahoo cookies stolen by the attacker would have allowed him to hijack his victims' browser sessions, letting him gain access to all of their Yahoo Mail emails and any other account which uses cookies for the yahoo.com domain,“ is noted in their report.

    The number of users affected by this phishing attack has not been disclosed, but a Yahoo spokeswoman announced that the issue was fixed within hours since it came to their attention on Sunday. As a precaution, she also advised all users who visited the compromised page to reset their account password.

    Mike Perry, a security researcher and developer at Riverbed Technology, presented earlier this year at DEFCON a Gmail Account automatic hacking tool that uses the same principle of stealing authentication cookies. Later, he released a tool named CookieMonster which is able to automate man-in-the-middle attacks and steal such cookies for many popular websites like Bank of America, Register, NetFlix, NewEgg, eBay and others.

  2. #2
    Experienced User
    Points: 25,838, Level: 96
    Level completed: 49%, Points required for next Level: 512
    Overall activity: 0.7%
    Achievements:
    31 days registered3 months registered1 year registeredVeteran100 Experience Points

    Join Date
    Sep 2007
    Location
    L*N*D*N
    Posts
    2,977
    Liked
    0 times
    Shows us that Yahoo! is not the safest website as some people think..

 

 

Similar Threads

  1. Replies: 0
    Last Post: 08-04-2011, 08:24 PM
  2. Twitter phishing attack spreads via Direct Messages !!!
    By INDRANIL in forum Spyware/Viruses
    Replies: 0
    Last Post: 07-10-2011, 10:07 PM
  3. Email phishing attack spreads to Gmail and Yahoo
    By ripper in forum Spyware/Viruses
    Replies: 10
    Last Post: 10-11-2009, 12:18 AM
  4. Paypal SCAM (phishing-attack) In Action
    By Swarup in forum Chat
    Replies: 1
    Last Post: 09-24-2009, 04:55 AM
  5. www.yahoo.com redirected to in.yahoo.com
    By Solaris in forum General Forum
    Replies: 8
    Last Post: 08-06-2008, 09:31 PM
All times are GMT +8. The time now is 10:27 PM.