Yahoo patches vulnerability allowing hackers to eavesdrop on emails

jayar.decenella@gmail.com' By: Jay Decenella
2 minute read

Yahoo has fixed a flaw in its Mail service that could have allowed hackers to eavesdrop on user emails nearly a year after the same bug was disclosed and patched. Jouko Pynnonen from Finland received $10,000 from Yahoo for disclosing the new vulnerability, which Yahoo fixed last month.

The flaw concerned a cross-site scripting attack that gave an attacker the permission to read a user’s email or create a virus to infect Yahoo Mail accounts. Pynnonen explained that a user must view the email from an attacker for the bug to work.

The bug was similar to an old Yahoo Mail flaw that Pynnonen discovered last year that could give hackers complete control of a Yahoo Mail account.

Shortcoming in Yahoo filters

Pynnonen cited a shortcoming in Yahoo’s filter for HTML messages as the culprit for the latest vulnerability. The filter works to block malicious code from the user’s browser. According to the researcher, the filter failed to capture all of the malicious data attributes. A hacker could then execute malicious JavaScript just by sending a custom email to the victim.

The researcher discovered the flaw in the email composing view, where various attachment options called his attention to potential bug in basic HTML filtering. Pynnonen then created an email with various attachments and sent the message to an external mailbox. Upon inspecting the raw HTML contained in the email, some malicious attributes caught his attention.

“What caught my eye were the data-* HTML attributes. First, I realised my last year’s effort to enumerate HTML attributes allowed by Yahoo’s filter didn’t catch all of them.”

Pynnonen thought it was possible to embed several HTML attributes that would pass through Yahoo’s HTML filter. He eventually found a pathological case after composing an email with abusive data-* attributes.

Yahoo has been under fire earlier this year following reports that indicate at least 200 million Mail accounts were sold on the dark web.

Read also:

For various PC problems, we recommend this tool.

This software will repair common computer errors, protect you from file loss, malware, hardware failure and optimize your PC for maximum performance. Fix PC issues now in 3 easy steps:

  1. Download this PC Repair Tool rated "Excellent" on TrustPilot.com.
  2. Click “Start Scan” to find Windows issues that could be causing PC problems.
  3. Click “Repair All” to fix all issues with Patended Technologies (requires upgrade).

Discussions

Next up

Best Windows 10 antivirus software to use in 2018

By: Radu Tyrsina
7 minute read

Update – 2018 will soon come to an end and we already have a guide on what is the best antivirus you should get in […]

Continue Reading

These features are out for good with Windows 10 version 1809

iamsovy@gmail.com' By: Sovan Mandal
2 minute read

Microsoft is all set to launch its next big update, Windows 10 version 1809 in October. While that should be a nice piece of news […]

Continue Reading

Windows 10 18H2 builds no longer receive new features

By: Matthew Adams
3 minute read

The Windows 10 October 2018 Update (otherwise 18H2) rollout might now be two to three weeks away. For the last few months, new build previews […]

Continue Reading