Yahoo Mail "fall" after 4 minutes

Missing 1 second, you will lose control of the mail box.
A hacker posted a YouTube video describing how easy it was to get into a victim's Yahoo account by tricking them into clicking on a link.
Over the weekend, a number of Yahoo Mail users have been forced to suspend their accounts after they had clicked on a link received in the mailbox (apparently sent from their friends). Yahoo said it had patched the flaw, but security experts said the problem was not resolved.
       . Some great tips in Yahoo! Mail
A hacker named Shahin Ramezany has conducted a self-published attempt to exploit the DOM-Based XSS vulnerability to gain access to the mailbox. When the victim clicks on the URL, the cookies (the user's activity on the web are saved by the browser) will be immediately sent to the attacker's computer and the user will use that cookie to enter the account. This trick can be applied on all popular browsers such as Internet Explorer, Chrome, Firefox ...
Then, the bad guys can use that mailbox to continue spreading malicious links to the victim's friends. Therefore, the security advised users should carefully consider before clicking on any content, whether sent by the acquaintance.

Nhận xét

Bài đăng phổ biến từ blog này

Yahoo discontinued using ImageMagick because of the YahooBleed vulnerability

Three interesting things about Yahoo Mail

Yahoo! Escalation in the battle with Facebook