New worm intended to harm Yahoo's mail service

Aug 13, 2007 13:23 GMT  ·  By

Security company Symantec detected a new threat that is meant to harm Yahoo Mail and to exploit a vulnerability that seems to exist in the Sunnyvale company's email product. JS.Yamanner@m is a worm created in JavaScipt that cannot be executed in the last version of Yahoo Mail Beta so only the users of the classic flavor of the mail solution can be affected by the threat. According to Symantec, the worm is sent as a HTML email message with Java content and, once the email is opened by the user, it starts several dangerous actions. First of all, it tries to exploit a vulnerability discovered into Yahoo Mail that would allow the worm to conduct the entire attack.

Then, it automatically scans the content of the Yahoo Mail account and copies the email addresses ending in @yahoo.com or @yahoogroups.com. The list is then transferred to a malicious website while the user is also redirected to this page.

As usual, you're encouraged to update your antivirus solution to the latest version of the virus definitions and avoid opening untrusted messages coming into your Yahoo Mail inbox.

Yahoo Mail has always been one of the most attacked email solutions on the Internet because a huge number of consumers are registered for this product. In comparison with Gmail that is often described as a more secure email service, Yahoo's product was often criticized for its weak filters that allow the spam messages to invade our inboxes.

However, Yahoo Mail remains very popular and the recent implementation of Yahoo Messenger makes it even more attractive for the Internet users. As you probably know, Yahoo Messenger is surely the leader of the online instant messaging clients as millions of consumers communicate on the Internet using the giant portal's application and the great functions it offers.