Yahoo swats serious cross-site scripting bug

Yahoo plugs cross-site scripting flawWeb application security firm Cenzic has flagged a serious cross-site scripting vulnerability affecting millions of Yahoo Mail users.

The flaw, which was patched by Yahoo on June 13,  opened the door for hackers to steal Yahoo identities and gain access to users’ sensitive and private information.

The skinny, via a Cenzic advisory:

If the attacker is using the Yahoo! Messenger desktop application 8.1.0.209 to chat with the victim, and the victim is using the Messenger support in the new Yahoo! Mail Web application, it will cause a new chat tab to open in the victim’s browser. While chatting, the attacker can change their status to “invisible” causing a message of “offline” in the chat tab of the victim. The vulnerability occurred when the attacker then changed status, and sent a custom message containing a malicious string in the form of a status message of “online,” with the script executed in the context of Yahoo! Mail on the victim’s machine. This allowed an attacker to get active access to the victim’s session ID, and in turn steal their Yahoo! identity, exposing sensitive personal information stored in their Yahoo! account.

[ ALSO SEE: Firefox raises barrier to cross-site scripting attacks ]

[Source: zdnet]

0 comments