Moneycontrol PRO
HomeNewsTechnologyYahoo Mail hacked via XSS exploit, loophole fixed soon after

Yahoo Mail hacked via XSS exploit, loophole fixed soon after

Reports about a malicious link compromising the security of several Yahoo! Mail accounts surfaced yesterday. The Next Web reports that a hacker...

January 08, 2013 / 17:20 IST

Reports about a malicious link compromising the security of several Yahoo! Mail accounts surfaced yesterday. The Next Web reports that a hacker going by the name Shahin Ramezany uploaded a YouTube video demonstrating how a Yahoo! account can be compromised with a DOM-based XSS vulnerability that can be misused across all major browsers. Ramezany’s technique, as depicted in the video, comes across as simple and and can be done in a short time. In fact,  if Ramezany is to be believed, then as many as 400 million Yahoo! Mail users faced the risk of becoming victims of this vulnerability. Folks at TNW soon got in touch with Yahoo! to know more on the issue and this is what a Yahoo! spokesperson in the UK had to say, "We’ve been looking into it and the US have now confirmed that they are investigating too. They will be in touch if there is a comment – otherwise I recommend that if users are concerned then they should change their passwords immediately."  Click here for full story

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

first published: Jan 8, 2013 04:51 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347