yahoo mail

Yahoo code vulnerability helps phishers

yahoo mailΟ and security researcher Kugler has warned her for a long time Yahoo that there are vulnerabilities in its code, but the company seems to ignore it.

Kugler has found that Yahoo has a vulnerability that allows attackers to redirect their victims to any site of their choice, with a URL from domain yahoo.com. The technique is called open redirect or open and helps cheats to trick their victims who trust domain yahoo.com.

In one of his publications, Kugler shows how yahoo.com can redirect to google.com:

Although the end of the URL indicates that something might be wrong, it just encodes the URL of the redirect hiding its tracks:

http://us.ard.yahoo.com/SIG=15n3q5c29/M=289534.11223993.11781333.10885343/D=he/S=18343859:FOOT2

Yahoo believes that there is no vulnerability, although redirects are the favorite technique of phishers.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).