Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

February 4th, 2013, 07:58 GMT · By

BLOG

Yahoo! Fixes XSS Vulnerability Leveraged by Hackers to Hijack Accounts

SHARE:

Adjust text size:


Yahoo! fixes XSS vulnerability in Developer Network Blog Enlarge picture - Yahoo! fixes XSS vulnerability in Developer Network Blog
Last week, Bitdefender experts detailed a cybercriminal scheme in which the attackers leveraged a cross-site scripting vulnerability present on the Yahoo! Developer Network Blog to steal user cookies and hijack sessions. Now, Yahoo! claims to have addressed the issues.

The hackers sent out spam emails containing a link apparently pointing to an MSNBC article.

Users who clicked on the link were directed to a JavaScript which exploited the flaw in the Yahoo! Developer Network Blog in order to steal authentication cookies.

The cybercriminals utilized these session cookies to gain access to the victims’ accounts, which they used to send out more spam emails.

The Yahoo! blog was vulnerable because it utilized an outdated version of WordPress.

Yahoo! representatives have told PCWorld that the security hole has been addressed. The company urges customers who are concerned for the safety of their accounts to change their passwords and enable two-factor authentication.

TELL US WHAT YOU THINK:

1,333 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Hackers Hijack Yahoo! Accounts by Stealing Authentication Cookies

Kevin Mitnick: The Increase of XSS Attacks in Q4 2012 Is Not Surprising

Experts Find Vulnerabilities in nCircle PureCloud Security Scanner

Expert Finds DOM-Based XSS Vulnerabilities on Kaspersky, Panda and AVG Sites

Microsoft Addresses XSS Vulnerability on Delish

READER COMMENTS:


Comment #1 by: dt on 09 Apr 2013, 12:52 UTC reply to this comment

So why's it still happening?

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM