You are here: silicon.com > Software > Security Strategy

Security Strategy

Yahoo! fixes webmail flaws

Malicious actions kept at bay...

By Robert Lemos

Published: 20 August 2004 08:35 GMT

Yahoo! has fixed two flaws in its free email system that could have allowed a malicious user to read a victim's browser cookies and change the appearance of some pages.

A representative of the company said the flaws were fixed last month by making changes on the company's Yahoo! Mail servers.

A Yahoo! spokeswoman said: "We were alerted of it at the end of May, early June. There ended up being two variations of the issue: One which we could reproduce in a few days and the other which took a lot of effort to reproduce."

The vulnerabilities are of a type known as cross-site scripting flaws, which typically take advantage scripting languages and misconfigured web servers to launch attacks against a user's computer. The attacks typically redirect the user to another website, allow access to the user's cookies or, sometimes, allow the attacker to run code on the victim's computer.

Yahoo! fixed the flaws in its server code. No patch is required by the Yahoo! Mail users.

Robert Lemos writes for News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
PPC (Pay Per Click) Search Executive / Manager

You will manage a portfolio of clients and specifically improve paid search campaigns in Google, MSN and Yahoo by using techniques such as Keyword ...

CSS Front End Web Developer - South Birmingham

In addition to the website work, the candidate will be responsible for other web design based activities such as producing HTML emails, promotional ...

Interface Developer

You will be responsible for estimating and completing the development and unit testing of web pages, scripts, programs or modules on a specific ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: