Advertisement
Promo

Security threats Toolkit

Yahoo passwords exposed by Zimbra

Elinor Mills CNET News

Published: 30 Sep 2008 12:07 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Passwords used to access Yahoo Mail through the Zimbra client are sent over the internet in clear text, a Canadian programmer has said.

Holden Karau stumbled upon the problem while participating in the Yahoo University Hack Day at the University of Waterloo in Ontario, Canada, last week.

"The Yahoo IMAP servers used by the Yahoo desktop don't support SSL and the password was being transmitted in plain text," Karau wrote in a blog post on Friday.

"What does this mean for you? If you use Zimbra to access your Yahoo mail, you almost certainly need to change your password and stop using Zimbra immediately (especially if you've ever done so over wireless)," he wrote.

Unsurprisingly, Karau's hack didn't place in the competition.

Read this

Q&A
Flickr founder offers snapshot of Yahoo life

Having recently left Yahoo, Flickr's parent company, Stewart Butterfield shares his thoughts on the inner workings of the web giant and its romance with Microsoft

Read more +

"In retrospect, it probably wasn't the best forum to bring up the security defects, but it was the most convenient," Karau said.

He notified Yahoo about the problem during his presentation but no-one seemed concerned, wrote Karau in a post on Zimbra Forums.

In a different post in that forum thread, a Zimbra representative wrote: "This problem has already been addressed in code, and fix is in the next release."

A Yahoo spokeswoman said she would check into the matter.

Credit: Yahoo's Zimbra e-mail program exposes passwords from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters