Breaking News

Apple unleashes M5 CPU and new devices PlayStation Plus Game Catalog for October 2025 Logitech Muse, the Digital Pencil for Apple Vision Pro, Launches October 22nd NIKON EXPANDS DX LENS LINEUP WITH TWO NEW NIKKOR LENSES MSI Unveils the AI-Ready Cubi Z AI Series Mini PC

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Yahoo Blog Hijacked, Bitdefender Says

Yahoo Blog Hijacked, Bitdefender Says

Enterprise & IT Jan 31,2013 0

An email-based attack has been hijacking Yahoo accounts, security software company Bitdefender Labs has reported. The security firm warned that a spam wave that has been circulating for roughly a month has been stealing Yahoo login credentials by exploiting an old vulnerability in a component of the Yahoo Developers blog.

The spam message features a bit.ly shortened URL that takes the user to a web page impersonating the popular MSNBC page, but which turns out to be located on a series of subdomains on hxxp://com-im9.net.

Whois information for the domain reveals it was bought in Ukraine and hosted in a data center in Nicosia, Cyprus, Bitdefender says.

Once the user lands on the alleged MSNBC page, a piece of JavaScript code inside tries to exploit a known vulnerability (CVE-2012-3414) in the SWF Uploader component on the Yahoo Developers Blog, which is powered by WordPress.

Since the exploitable component is located on a sub-domain of the target website, the same-origin policy does not prevent the exploit code access to cookies, which are subsequently sent to the attacker. Once they have the log-in cookie, they can authenticate into the victim's account and send spam or harvest contacts' e-mail addresses for other spam campaigns.

Bitdefender's experts believe this is the account recruitment stage of the operation and we expect the next wave of messages to feature links to malware.

Bitdefender said it had notified Yahoo about the incident and had provided the proof-of-concept documentation.

Tags: Yahoo
Previous Post
Up To $80 Discount For CyberLink's PowerDirector 11 Software
Next Post
DVD and Blu-ray Still Drive Home Entertainment Revenue

Related Posts

  • Yahoo and Verizon Launch Yahoo Mobile Unlimited Phone Service

  • Yahoo Groups Website is Closing

  • Yahoo Together Comes to Organize Group Messaging

  • Altaba Sells Yahoo Japan stake for $4.3 billion

  • Japan Accuses Apple of Pressuring Game Rivals: Nikkei

  • Oath Scans Your Yahoo and AOL Mail for Targeted Advertising

  • Mozilla Files Cross-Complaint Against Yahoo and Oath

  • Yahoo Says All 3 Billion Accounts Were Hacked in 2013 Security Breach

Latest News

Apple unleashes M5 CPU and new devices
Enterprise & IT

Apple unleashes M5 CPU and new devices

PlayStation Plus Game Catalog for October 2025
Gaming

PlayStation Plus Game Catalog for October 2025

Logitech Muse, the Digital Pencil for Apple Vision Pro, Launches October 22nd
Consumer Electronics

Logitech Muse, the Digital Pencil for Apple Vision Pro, Launches October 22nd

NIKON EXPANDS DX LENS LINEUP WITH TWO NEW NIKKOR LENSES
Cameras

NIKON EXPANDS DX LENS LINEUP WITH TWO NEW NIKKOR LENSES

MSI Unveils the AI-Ready Cubi Z AI Series Mini PC
Enterprise & IT

MSI Unveils the AI-Ready Cubi Z AI Series Mini PC

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Pure Base 501

be quiet! Pure Base 501

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed