On TV.com: TOP 10 Shows CANCELED Too Soon
BNET Business Network:
BNET
TechRepublic
ZDNet

October 27th, 2008

HotJobs site flaw leads to Yahoo account theft

Posted by Ryan Naraine @ 12:53 pm

Categories: Anti Virus, Botnets, Browsers, Data theft, Exploit code, Malware, Passwords, Patch Watch, Phishing, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research, Web 2.0

Tags: Attacker, Flaw, Yahoo! Inc., Authentication, HotJobs, Netcraft, Cookie, Security, Ryan Naraine

Phishing for Yahoo accounts(See update below for statement from Yahoo).

Malicious hackers are exploiting a cross-site scripting flaw on Yahoo’s HotJobs site to phish for Yahoo credentials, according to a warning from Netcraft.

In the ongoing attack, Netcraft discovered that the vulnerability allows the attacker to inject obfuscated JavaScript into the affected page to steal authentication cookies that are sent for the yahoo.com domain.

The stolen authentication cookies are then passed to a different web site in the United States, where the attacker is harvesting stolen authentication details.

  • Simply visiting the malign URLs on yahoo.com can be enough for a victim to fall prey to the attacker, letting him steal the necessary session cookies to gain access to the victim’s email — the victim does not even have to type in their username and password for the attacker to do this. Both attacks send the victim to a blank webpage, leaving them unlikely to realise that their own account has just been compromised.

Netcraft said it notified Yahoo of the latest attack but warned that the HotJobs vulnerability and the attacker’s cookie harvesting script are both still present at the vulnerable site.

UPDATE:  Yahoo e-mailed the following in response to this story:

The team was made aware of this particular Cross-Site Scripting issue yesterday morning (Sunday, Oct. 26) and a fix was deployed within a matter of hours. Yahoo! appreciates Netcraft’s assistance in identifying this issue.

As a safety precaution, we recommend users change their passwords, should they still be concerned. Users should always verify via their Sign-in Seal that they are giving their passwords to Yahoo.com.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 1 Talkback(s)
Surely Blocked by NoScript!  mejohnsn | 04/30/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads