Breaking News

Viltrox Launches AF 75mm F1.8 EVO and AF 90mm F2.2 Lenses COLORFUL Unveils New iGame M15 and M16 Origo Gaming Laptops at COMPUTEX 2026 GIGABYTE Showcases Sleek STEALTH and Elegant WOOD PC Builds at COMPUTEX 2026 GIGABYTE Showcases Industry-leading CQDIMM Performance and Ecosystem Expansion at COMPUTEX 2026 G.SKILL Demos Trident Z5 NeoX RGB Series DDR5 with AMD EXPOT Technology

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Yahoo Blog Hijacked, Bitdefender Says

Yahoo Blog Hijacked, Bitdefender Says

Enterprise & IT Jan 31,2013 0

An email-based attack has been hijacking Yahoo accounts, security software company Bitdefender Labs has reported. The security firm warned that a spam wave that has been circulating for roughly a month has been stealing Yahoo login credentials by exploiting an old vulnerability in a component of the Yahoo Developers blog.

The spam message features a bit.ly shortened URL that takes the user to a web page impersonating the popular MSNBC page, but which turns out to be located on a series of subdomains on hxxp://com-im9.net.

Whois information for the domain reveals it was bought in Ukraine and hosted in a data center in Nicosia, Cyprus, Bitdefender says.

Once the user lands on the alleged MSNBC page, a piece of JavaScript code inside tries to exploit a known vulnerability (CVE-2012-3414) in the SWF Uploader component on the Yahoo Developers Blog, which is powered by WordPress.

Since the exploitable component is located on a sub-domain of the target website, the same-origin policy does not prevent the exploit code access to cookies, which are subsequently sent to the attacker. Once they have the log-in cookie, they can authenticate into the victim's account and send spam or harvest contacts' e-mail addresses for other spam campaigns.

Bitdefender's experts believe this is the account recruitment stage of the operation and we expect the next wave of messages to feature links to malware.

Bitdefender said it had notified Yahoo about the incident and had provided the proof-of-concept documentation.

Tags: Yahoo
Previous Post
Up To $80 Discount For CyberLink's PowerDirector 11 Software
Next Post
DVD and Blu-ray Still Drive Home Entertainment Revenue

Related Posts

  • Yahoo and Verizon Launch Yahoo Mobile Unlimited Phone Service

  • Yahoo Groups Website is Closing

  • Yahoo Together Comes to Organize Group Messaging

  • Altaba Sells Yahoo Japan stake for $4.3 billion

  • Japan Accuses Apple of Pressuring Game Rivals: Nikkei

  • Oath Scans Your Yahoo and AOL Mail for Targeted Advertising

  • Mozilla Files Cross-Complaint Against Yahoo and Oath

  • Yahoo Says All 3 Billion Accounts Were Hacked in 2013 Security Breach

Latest News

Viltrox Launches AF 75mm F1.8 EVO and AF 90mm F2.2 Lenses
Cameras

Viltrox Launches AF 75mm F1.8 EVO and AF 90mm F2.2 Lenses

COLORFUL Unveils New iGame M15 and M16 Origo Gaming Laptops at COMPUTEX 2026
Consumer Electronics

COLORFUL Unveils New iGame M15 and M16 Origo Gaming Laptops at COMPUTEX 2026

GIGABYTE Showcases Sleek STEALTH and Elegant WOOD PC Builds at COMPUTEX 2026
Cooling Systems

GIGABYTE Showcases Sleek STEALTH and Elegant WOOD PC Builds at COMPUTEX 2026

GIGABYTE Showcases Industry-leading CQDIMM Performance and Ecosystem Expansion at COMPUTEX 2026
PC components

GIGABYTE Showcases Industry-leading CQDIMM Performance and Ecosystem Expansion at COMPUTEX 2026

G.SKILL Demos Trident Z5 NeoX RGB Series DDR5 with AMD EXPOT Technology
PC components

G.SKILL Demos Trident Z5 NeoX RGB Series DDR5 with AMD EXPOT Technology

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

be quiet! Pure power 13M 750W

be quiet! Pure power 13M 750W

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed