Get a Pentest and security assessment of your IT network.

News

Seizing Control of Yahoo! Mail Cross-Origin Again

This is a follow-up to another article about crossorigin mail theft on Yahoo! Mail using Flash. Flash has a feature where you can embed a crossorigin.swf inside your own own own.swf. The crossorigin proxy has since been patched, but the loose crossdomain.xml rules remain. How can we exploit these rules without using MITM attacks? Well, we abuse vulnerabilities in.swfs that are legitimately hosted on subdomains of yahoo.com.”]

Source: http://blog.saynotolinux.com/blog/2014/12/09/seizing-control-of-yahoo-mail-cross-origin-again/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

IntelCrawler profiled Syrian Electronic Army group

News

Wikileaks Vault 7 Imperial projects revealed the 3 hacking tools Achilles, SeaPea and Aeris