Vulnerability in Yahoo, Microsoft, and Orange high profile subdomains

Security researcher Ebrahim Hegazy found a vulnerability that allowed remote code in its subdomains YahooOf Microsoft and Orange. Fortunately, the security gap has already been determined by company technicians.

yahoo admin

The expert discovered the flaw by analyzing one της Yahoo στο Μεξικό (το mx.horoscopo.yahoo.net). Στο συγκεκριμένο subdomain εντοπίστηκε ένα διαχειριστικό πανελ που θα μπορούσε να προσεγγιστεί χωρίς διαπιστευτήρια σύνδεσης. Ο ερευνητής αποκάλεσε την ευπάθεια αυτή “μη εξουσιοδοτημένη πρόσβαση Διαχειριστή” ή “Εμεσο αντικείμενο αναφοράς” (Unauthorized Admin or Indirect Object Reference)

From this open panel, Hegazy managed to upload his own aspx file to the server. These files could comfortably contain code that would allow an attacker to execute arbitrary code, experts say in his blog. However, the file was loaded for research purposes and contained only a single string.

After identifying the vulnerability, he tried to examine other Yahoo sybdomains. To his surprise, he discovered that the vulnerability not only existed in not only Yahoo's subdomains, but also Microsoft's MSN subdomains as well as the French of Orange telecommunications.

“The shocking thing is that I did not upload / create my page in each domain to make a good POC! I just created this page in one of the domains (pe.horoscopo.yahoo.net, ar.horoscopo.yahoo.net, co.horoscopo.yahoo.net, cl.horoscopo.yahoo.net, astrocentro.latino.msn.com , astrologia.latino.msn.com, horoscopo.es.msn.com, horoscopos.prodigy.msn.com, and astrocentro.mujer.orange.es) by Yahoo, I discovered that my page has been created on all sites that are hosted on the same server, Yahoo, MSN, Orange and others, ”says the researcher.

"Imagine using this vulnerability hackers, creating an "Iframed" aspx page with malicious content on such high-profile domains as Yahoo.net, MSN.com and Orange.es."

The researcher reported his findings at Microsoft, Yahoo and Orange. Orange has not responded to the announcement, while Yahoo has decided to reward the expert.

For more technical details on vulnerability, visit Hegazy's website.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).