Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • PM Modi in Manipur
  • Charlie Kirk killer
  • Sushila Karki
  • IND vs PAK
  • India-US ties
  • New human organ
  • Downton Abbey: The Grand Finale Movie Review
fp-logo
Yahoo Mail hacked via XSS exploit, loophole fixed soon after
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Yahoo Mail hacked via XSS exploit, loophole fixed soon after

Yahoo Mail hacked via XSS exploit, loophole fixed soon after

Anuradha Shetty • January 8, 2013, 16:51:07 IST
Whatsapp Facebook Twitter

Reports about a malicious link compromising the security of several Yahoo! Mail accounts surfaced yesterday. The Next Web reports that a hacker…

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Yahoo Mail hacked via XSS exploit, loophole fixed soon after

Reports about a malicious link compromising the security of several Yahoo! Mail accounts surfaced yesterday. The Next Web reports that a hacker going by the name Shahin Ramezany uploaded a YouTube video demonstrating how a Yahoo! account can be compromised with a DOM-based XSS vulnerability that can be misused across all major browsers. Ramezany’s technique, as depicted in the video, comes across as simple and and can be done in a short time. In fact,  if Ramezany is to be believed, then as many as 400 million Yahoo! Mail users faced the risk of becoming victims of this vulnerability. Folks at TNW soon got in touch with Yahoo! to know more on the issue and this is what a Yahoo! spokesperson in the UK had to say, “We’ve been looking into it and the US have now confirmed that they are investigating too. They will be in touch if there is a comment – otherwise I recommend that if users are concerned then they should change their passwords immediately.”  

STORY CONTINUES BELOW THIS AD

cover

Hacking attack but fixed

The spokesperson added, “At Yahoo! we take security very seriously and invest heavily in measures to protect our users and their data. We were recently informed of an online video that demonstrated a vulnerability. We confirm that the vulnerability has been fixed. In addition, we are investigating recent reports of increased abusive traffic and will work diligently to fix any vulnerabilities that are found. Concerned users are encouraged to change their passwords to a safe password that combines letters, numbers, and symbols.”

More from News & Analysis
What is the US HIRE Bill and why is India’s $250-billion IT sector worried? What is the US HIRE Bill and why is India’s $250-billion IT sector worried? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true?

Twitter is abuzz with comments from those whose accounts were compromised in the attack. One user (Twitter handle - @mygzyap) wrote, “Seems someone tried to hack my Yahoo mail account. If you receive rogue e-mails from me, please let me know.” Another one (Twitter handle - @ronicadesign) wrote, “My crap @yahoo email got hacked *again*. Deleted all my contacts about a yr. ago, after the first hack & it still sent out spam. DELETED.”

In July last year, hackers belonging to a hacking collective called D33Ds Company retrieved and dumped login details of more than 400,000+ user accounts in plain text. A post on Trustedsec stated, “The passwords contained a wide variety of email addresses including those from yahoo.com, gmail.com, aol.com, and much more.” Interestingly, the post added that the affected website was a sub-domain of yahoo.com and that the compromised server may be Yahoo! Voice a.k.a Associated Content. “The affected website was only named as a sub-domain of yahoo.com. However, digging through and searching for the hostname, the attacker forgot to remove the hostname “dbb1.ac.bf1.yahoo.com” (credit to Mubix for the hostname find),” Trustedsec wrote. The most worrisome bit was that the passwords that were stored were completely unencrypted, and as you’re reading this, 400,000+ login credentials (comprising usernames and passwords) have been exposed.

It had been brought to light that the hackers used a union-based SQL injection attack to get away with the information stored in the database. The post on Trustedsec also put forth a glimpse of what the data leaked online looks like. 

A note at the end of the dump read, “We hope that the parties responsible for managing the security of this sub-domain will take this as a wake-up call and not as a threat. There have been many security holes exploited in webservers belonging to Yahoo! Inc. that have caused far greater damage than our disclosure. Please do not take them lightly. The sub-domain and vulnerable parameters have not been posted to avoid further damage.”

STORY CONTINUES BELOW THIS AD

Reporting on the issue, Ars Technica’s Dan Goodin wrote that the union-based SQL injection hacking technique used here affects inadequately secured web applications that do not “properly scrutinize text entered into search boxes and other user input fields”. He added, “By injecting powerful database commands into them, attackers can trick back-end servers into dumping huge amounts of sensitive information.”

Tags
Yahoo! Yahoo Mail Web services SQL Injection Attack union based SQL injection attack Yahoo Mail breach
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV