Get a Pentest and security assessment of your IT network.

News

Attackers can abuse Yahoo developer feature to steal user emails, other data

Attackers can read emails, contacts and other private data from Yahoo accounts of Yahoo users who visit malicious websites. A limited version of the attack was presented on Sunday at the DefCamp security conference in Bucharest, Romania, by a Romanian Web application bug hunter named Sergiu Dragos Bogdan. Bogdan presented a proof-of-concept (PoC) attack page that loaded a specific developer.yahoo.com URL inside an iframe. When the attack page was visited by an authenticated Yahoo user — a test account — the iframe returned the visitor’s crumb code.”]

Source: https://www.csoonline.com/article/2132605/attackers-can-abuse-yahoo-developer-feature-to-steal-user-emails–other-data.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Terrorism WEEKLY DIGESTTHREAT INTELLIGENCE FEED 23rd Jul 2nd

News

Attacker.NET : Server Management & Security, Website Malware Removal & Website Security