You are here: silicon.com > Software > Security Strategy

Security Strategy

Yahoo! fixes webmail flaws

Malicious actions kept at bay...

By Robert Lemos

Published: 20 August 2004 08:35 BST

Yahoo! has fixed two flaws in its free email system that could have allowed a malicious user to read a victim's browser cookies and change the appearance of some pages.

A representative of the company said the flaws were fixed last month by making changes on the company's Yahoo! Mail servers.

A Yahoo! spokeswoman said: "We were alerted of it at the end of May, early June. There ended up being two variations of the issue: One which we could reproduce in a few days and the other which took a lot of effort to reproduce."

The vulnerabilities are of a type known as cross-site scripting flaws, which typically take advantage scripting languages and misconfigured web servers to launch attacks against a user's computer. The attacks typically redirect the user to another website, allow access to the user's cookies or, sometimes, allow the attacker to run code on the victim's computer.

Yahoo! fixed the flaws in its server code. No patch is required by the Yahoo! Mail users.

Robert Lemos writes for News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey The rise and rise of Infor Quocirca's Straight Talking: Where next for the apps giant?

Inbox: Vista, Bletchley Park and Cuil "Windows 98 was a far better and more capable OS..."


  • Jobs
Strong JavaScript Developer / HTML / CSS / Ajax / Cross Browser - ASAP

You will have good experience of Java and Scripting Libraries as well as good working knowledge of Cross Browser Application. I am looking for a ...

Web Project Manager/Web Services Architect 160 - 180 p/d 12months

Knowledge of, JavaScript, ; Familiarity with scripting languages such as J2EE, Power Shell, Familiar with the MS technologies such as Windows ...

Front End Developer - User Interface - Media

You will have experience creating tableless layouts and cross browser and cross platform issues. If you have knowledge of JavaScript/ DOM Scripting/ ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: