Raymond.CC Blog








Go Back   Raymond.CC Forum > Computer Related Forum > Spyware/Viruses

Reply
 
Thread Tools Display Modes
  #1 (permalink)  
Old 10-28-2008
shan's Avatar
shan shan is online now
Star
 
Join Date: Jun 2008
Location: Sri Lanka
Posts: 1,933
Phishing Attack Uses Yahoo HotJobs XSS Vulnerability



Netcraft, a British company that offers Internet and security services, announced that a phishing attack was compromising Yahoo accounts. According to the company, the attack was using obfuscated JavaScript code injected in the hotjobs.yahoo.com website in order to gather authentication cookies from users accessing the page. Yahoo was notified and fixed the problem.

The attackers used a cross-site scripting vulnerability in the Yahoo! HotJobs website in order to inject malicious obfuscated JavaScript code into the page. The JavaScript code was used to pass the authentication cookies sent by the browsers to another external website set up by the attackers in the US. Using the stolen cookies, the attackers hijacked the user sessions and gained access to all Yahoo services that required authentication.

An authentication cookie is a text file served by the web server to the user's browser after a successful login. The file allows the web server to keep the session opened for a period of time or until the user logs out. When trying to access a resource that requires authentication, the web server asks the browser for this cookie file. If the file exists and the browser is able to return it, the web server allows access to the resource.

According to Netcraft, enforcing HTTP-only cookies, which are supported by all modern browsers, would have mitigated this attack, since cookies tagged with this attribute cannot be accessed by server-side scripts. The company also points out that a highly similar attack using Yahoo compromised pages was detected earlier this year.

“In both cases, Netcraft found that the Yahoo cookies stolen by the attacker would have allowed him to hijack his victims' browser sessions, letting him gain access to all of their Yahoo Mail emails and any other account which uses cookies for the yahoo.com domain,“ is noted in their report.

The number of users affected by this phishing attack has not been disclosed, but a Yahoo spokeswoman announced that the issue was fixed within hours since it came to their attention on Sunday. As a precaution, she also advised all users who visited the compromised page to reset their account password.

Mike Perry, a security researcher and developer at Riverbed Technology, presented earlier this year at DEFCON a Gmail Account automatic hacking tool that uses the same principle of stealing authentication cookies. Later, he released a tool named CookieMonster which is able to automate man-in-the-middle attacks and steal such cookies for many popular websites like Bank of America, Register, NetFlix, NewEgg, eBay and others.
Reply With Quote
Alt Today
Advertising
Google Adsense
 
Standard Sponsored Links
  #2 (permalink)  
Old 10-28-2008
bahirzaheri8's Avatar
bahirzaheri8 bahirzaheri8 is offline
Star
 
Join Date: Sep 2007
Location: L*N*D*N
Posts: 2,977
Shows us that Yahoo! is not the safest website as some people think..
__________________
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Yahoo URL http://m.www.yahoo.com/ luffy General Forum 6 11-10-2009 08:56 PM
Email phishing attack spreads to Gmail and Yahoo ripper Spyware/Viruses 10 10-10-2009 11:18 PM
Paypal SCAM (phishing-attack) In Action swarup1987 Chat 1 09-24-2009 03:55 AM
Phishing Warning! In-f3st General Forum 2 10-15-2008 11:23 AM
www.yahoo.com redirected to in.yahoo.com Solaris General Forum 8 08-06-2008 08:31 PM


All times are GMT +8. The time now is 05:06 PM.