Latest Comments
"lol"
by Tina | Jul 5, 2009 12:04 AM
 
"Good! Its very good blog the for the people who are having debit collection and credit report ..."
by identity theft lawyers | Jul 4, 2009 6:55 PM
 
"nothing"
by UMAIR | Jul 4, 2009 5:54 PM
 
"Thank you "
by Dr. Holub | Jul 4, 2009 11:17 AM
 
"Agree that wireless hotspots are an easy way for hackers to gather information from connected ..."
by Patrick Hooper | Jul 3, 2009 4:06 AM

Yahoo's HotJobs site vulnerable to cross-site scripting attack

  • Email a Friend
  • Print Page
By Dan Kaplan
Oct 28, 2008 2:30 PM
Tags: Yahoo's | HotJobs | site | vulnerable | to | cross-site | scripting | attack
Internet research firm Netcraft said it has detected a cross-site scripting vulnerability on Yahoo that could be used to hijack authentication cookies.
Internet research firm Netcraft said it has detected a cross-site scripting vulnerability on Yahoo that could be used to hijack authentication cookies.

The flaw resides on Yahoo's HotJobs search engine site, on which hackers embedded malicious JavaScript code, Netcraft's Paul Mutton said.

"The script steals the authentication cookies that are sent for the Yahoo.com domain and passes them to a different website in the United States, where the attacker is harvesting stolen authentication details," Mutton wrote.

The pilfered credentials could enable the attackers access to the victims' Yahoo acounts, including email. This vulnerability is similar to another bug that affected Yahoo earlier this year, he said.

"Simply visiting the malign URLs on Yahoo.com can be enough for a victim to fall prey to the attacker, letting him steal the necessary session cookies to gain access to the victim's email — the victim does not even have to type in their username and password for the attacker to do this," Mutton wrote. "Both attacks send the victim to a blank webpage, leaving them unlikely to realise that their own account has just been compromised."

He said websites must protect cookie values.

Netcraft notified Yahoo about the flaw.

A Yahoo spokeswoman could not be reached for comment on Monday.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Exclusive Data Centre - Sponsored Content by Microsoft
 
Vulnerabilities & Exploits Whitepapers