RE: [Full-disclosure] Vunerability in yahoo webmail.



Oh, I've CC'd abuse@xxxxxxxxx, but if someone else would give them a
proper write-up, and encourage
them to close the hole, that'd be wonderful.

Since yahoo isn't known for fixing bugs fast unless it's serious (and
even then), here's something i wrote up today.
The exploit is turned into a script-kiddish interface. Here's how it
works:
1) you enter your email and the target (@yahoo.com) email
2) an email with the exploit is sent to the target
3) when the target opens the mail for reading, cookies get stolen and
you get a notification on the address specified
4) further instructions on how to log in are on the site.

Tested on IExplore and Opera, works with both.

http://zmailhost.ath.cx/

(I'm taking it down when yahoo fixes it or people abuse it too much)

php0t@xxxxxxxx


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Relevant Pages

  • Re: Private IP address with yahoo messenger
    ... You can test it using yahoo booters and an authentic yahoo id both ... 2.Through packet malformation you can get information of the target IP ... Simply typing the text in chat window. ... thorough forensic analysis of the packets coming from target. ...
    (Security-Basics)
  • Re: Make
    ... > I am using the make utility to build a shared object. ... make the target depend on the ... Do You Yahoo!? ... Mail has the best spam protection around ...
    (RedHat)
  • Save Target As
    ... When I choose to save a message from my Yahoo! ... I generally do this: from my inbox (or ... outbox or sent box) ... Select "Save target As" - then I save it to a folder on ...
    (microsoft.public.internet.mail)
  • how to make my RAID device WORM(write once and read many)
    ... I am working Raid5 storage device and i want to make ... I formated the target device in vfat, ... i am mounting the device in host machine it should ... Do you Yahoo!? ...
    (freebsd-questions)