You are here: silicon.com > Software > Malware

Malware

Worm finds hole in Yahoo! Mail

Yamanner virus spotted in the wild...

Tags: worm, yamanner, computer worm, viruses worms

By Dawn Kawamoto

Published: 13 June 2006 09:05 GMT

A new worm that targets Yahoo! email users is on the loose, taking advantage of a JavaScript flaw, a security company has warned.

The Yamanner worm targets all versions of Yahoo! web-based mail except the latest beta version, Symantec said in an advisory released on Monday.

At the time of the advisory, there was no patch for the vulnerability. But by later on Monday, Yahoo! said it had come up with a fix for the flaw, which it said had affected very few of its customers.

A Yahoo! representative said: "We have taken steps to resolve the issue and protect our users from further attacks of this worm. The solution has been automatically distributed to all Yahoo! Mail customers, and requires no additional action on the part of the user."

Both Symantec and Yahoo! are encouraging people to update the antivirus definitions on their PCs.

Yamanner arrives in a Yahoo! mailbox bearing the subject header "New Graphic Site." Once the message is opened, the computer becomes infected and the worm spreads itself to people on the Yahoo! email contact list. The harvested email addresses are also sent to a remote online server, which Symantec suspects may use the information for spam campaigns.

Dean Turner, senior manager of Symantec Security Response, said: "The worm is taking a pretty novel approach. It takes advantage of a JavaScript vulnerability, so the user doesn't even have to click on an attachment to get infected."

The worm, which was spotted in the wild early this morning, has hit the remote server more than 100,000 times, forwarding Yahoo! email addresses harvested from unsuspecting users, Turner said.

Although it is spreading quickly, and no patch has been issued, Symantec is rating the threat a "2". The security vendor uses a 1-to-5 rating system, with "5" as its most severe category.

Turner said: "Antivirus definitions have been released for it and Yahoo! is working on a patch so we don't want to cry wolf. Although there is the potential the worm will affect a larger number of people, for now to raise it to another [higher] level would be inappropriate."

He added it is premature to predict whether this worm will morph into other forms and attack other browser-based forms of email, such as Google's Gmail.

Systems affected include Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003 and Windows XP, according to Symantec's advisory.

Dawn Kawamoto writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
QA Team Leader

Author to ensure new features/changes are documented accurately in the Help and Manuals * Act as a consultant for testing methodologies to be used ...

Systems Administrator

Change Control Forms * Microsoft qualification (MCSE, MCP, MCSA) * Symantec Anti Virus, Veritas, Netback up * Citrix thin Client This is a great ...

Senior 18 Week Information Analyst

In addition strong Access and Excel skills are required inclusive of pivot tables, writing macros, creating interactive forms. Successful applicants ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: