Advertisement
Promo

Security threats Toolkit

Yahoo corrects email flaw

Patrick Gray ZDNet Australia

Published: 22 Apr 2004 08:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Yahoo has fixed a bug in its Web-based email system that would have allowed attackers to seize control of users' email accounts.

The security flaw, discovered by eEye Digital Security's Drew Copley, allowed attackers to by-pass the Web-mail system's Javascript filters. Any message exceeding approximately 100kb in length would not be analysed by the filter, which is meant to strip messages of any potentially malicious Javascript.

In effect, this enabled attackers to take control of a user's account by sending them a specially crafted email.

"A remarkable note about this bug is that no one seems to have found it before," Copley's advisory reads. "As far as anyone knows."

Speaking to ZDNet UK sister site ZDNet Australia by phone from the US, Copley said it would be possible to use the flaw to capture the username and password of a Yahoo account holder.

"You can change the page that they're looking at. You can get all their contact information. You can do anything that a user would do on the page," he said. "The main thing people would do with this is to grab usernames and passwords through a re-login page."

This works by using Javascript to load a window that prompts the user to log in to the service again. However, when the user name and password are entered, they is sent to the attacker, not to Yahoo. It works somewhat like a phishing scam, Copley said.

The usual alarm bells would not ring for the average user, Copley added; Yahoo routinely prompts users with a window asking them to log in again following session time-outs.

The bug would also allow an attacker to seize the user's session cookie, which contains personal user details submitted to Yahoo. Copley has praised Yahoo's response to the issue.

"They were very professional and fixed it very quickly. I was impressed," he said.

The discovery of the bug did not come from hours of pain-staking research, Copley admits. He found it when another researcher, known as "http-equiv", sent him a virus, for research purposes, by email that was over 100kb in size.

"He was showing me a virus that was using one of my bugs in the wild. It had all this code, and one of the parts just started running," he explained. "We found it by accident."

For more coverage on ZDNet Australia, click here.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
82 out of 115 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

This Crap Site

How utterly stupid - I am ranked #40 in the top 100 - as a member of this site..... I mean HOW utterly stupid.... I have done sweet FA, I have only rejoined this site after a 3 or... More

Post a comment

Microsoft Security Update: November Pa...

Apologies for this late update to our core Patch Tuesday update. Here is a summary of the update .... The November Patch Tuesday update from Microsoft follows the largest patch and... More

Post a comment

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

4 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters