Culture and leisure


State


Industry


Transport


Science and engineering


Finances


Communication


IT, Media


Fuel and energy


Trade and Services


Physical activity


World


Русская версия


Login
✖
Loginor E-mail
Password
Remind password | Register
top news
.
The Central Bank lowered the dollar exchange rate
.
It became known about the death of the Ukrainian crew of the Mi-24 helicopter
.
Peskov called the messenger MAX convenient
.
Lukashenko praised joint import substitution projects with Russia
  • Oreanda-News.com
  • ›
  • Industry
  • ›
  • Yahoo email gets fix to nix sender-spoofing trickery
17.03.2016, 00:59

Yahoo email gets fix to nix sender-spoofing trickery

Industry
OREANDA-NEWS. March 17, 2016. The bug was discovered by independent researcher Lawrence Amer and published through Vulnerability Lab on Full Disclosure. On Monday, the security researcher released details of the flaw publicly, saying the sender-spoofing vulnerability affected the Yahoo webmail application.

Cyberattackers are able to remotely spoof the sender names of Yahoo email users through a vulnerability found within the "compose message" module of the Web service. A weakness in the system permits users to inject or intercept traffic in the POST/GET parameters, spoofing the email address to whatever sender name they wish.

This vulnerability is a problem as spoofed email addresses are often used in spear-phishing campaigns -- fraudulent emails sent for the purposes of information theft or to dupe victims into installing malware on their systems. If a user receives an email from a spoofed Yahoo address that seems legitimate, they may be more likely to fall for such a campaign.

The exploit is considered a medium severity issue, and the vulnerability has now been fixed. If you'd like, you can view the researcher's proof-of-concept video.

Yahoo was made aware of the flaw in October last year, and the Sunnyvale, California, company's developers were able to create a patch to fix the issue at the end of February. Amer submitted the email security flaw through Yahoo's Bug Bounty program, hosted on HackerOne. It's not known how much he earned for his work.

This story originally appeared at ZDNet under the headline "Yahoo patches sender spoofing email vulnerability."

Подпишитесь на каналы ИА "Ореанда-Новости":
VK News News


Другие новости:

Телегин: "Хоккеисты ЦСКА не мальчики для битья и будут сражаться до последнего"20.04.2018 23:27:46

Луис Энрике: "У "Сити" есть много вещей, которые мы не видели"01.11.2016 00:27:44

Share on social networks:
 Подписаться на наши группы: Instagram | VK | Facebook | Twitter


Rate this article:

Комментарии

Для добавления комментария необходимо войти под своей учётной записью или зарегистрироваться.
Loginor E-mail
Password
Remind password | Register
Комментариев нет

НОВОСТИ ПАРТНЁРОВ



Latest news in section

Russian Stock Market (MOEX): Share prices of development enterprises 18.12.2025, 16:30 MSK
18.12.2025 16:30
Russian Stock Market (MOEX): Share prices of chemical enterprises 18.12.2025, 15:00 MSK
18.12.2025 15:00
Russian Stock Market (MOEX): Share prices of metallurgy and mining enterprises 18.12.2025, 12:30 MSK
18.12.2025 12:30
AvtoVAZ will return to a five-day working week
17.12.2025 19:32
Russian Stock Market (MOEX): Share prices of development enterprises 17.12.2025, 16:29 MSK
17.12.2025 16:30
Russian Stock Market (MOEX): Share prices of chemical enterprises 17.12.2025, 14:59 MSK
17.12.2025 15:00
Russian Stock Market (MOEX): Share prices of metallurgy and mining enterprises 17.12.2025, 12:30 MSK
17.12.2025 12:30
Russian Stock Market (MOEX): Share prices of development enterprises 16.12.2025, 16:30 MSK
16.12.2025 16:30
Russian Stock Market (MOEX): Share prices of chemical enterprises 16.12.2025, 15:00 MSK
16.12.2025 15:00
Russian Stock Market (MOEX): Share prices of metallurgy and mining enterprises 16.12.2025, 12:30 MSK
16.12.2025 12:30
Russian Stock Market (MOEX): Share prices of development enterprises 15.12.2025, 16:30 MSK
15.12.2025 16:30
Russian Stock Market (MOEX): Share prices of chemical enterprises 15.12.2025, 15:00 MSK
15.12.2025 15:00
Russian Stock Market (MOEX): Share prices of metallurgy and mining enterprises 15.12.2025, 12:30 MSK
15.12.2025 12:30
Volkswagen announced the closure of the plant in Germany
15.12.2025 12:19
Government extends state support measures for coal companies
12.12.2025 23:02
Russian Stock Market (MOEX): Share prices of development enterprises 12.12.2025, 16:29 MSK
12.12.2025 16:30
Russian Stock Market (MOEX): Share prices of chemical enterprises 12.12.2025, 14:59 MSK
12.12.2025 15:00
Russian Stock Market (MOEX): Share prices of metallurgy and mining enterprises 12.12.2025, 12:29 MSK
12.12.2025 12:30
Russian Stock Market (MOEX): Share prices of development enterprises 11.12.2025, 16:30 MSK
11.12.2025 16:30
Russian Stock Market (MOEX): Share prices of chemical enterprises 11.12.2025, 14:59 MSK
11.12.2025 15:00
Russian Stock Market (MOEX): Share prices of metallurgy and mining enterprises 11.12.2025, 12:30 MSK
11.12.2025 12:30
Steel production in Russia has fallen
10.12.2025 20:39
Mash: Three popular Solaris models have been discontinued in Russia
10.12.2025 20:31
Russian Stock Market (MOEX): Share prices of development enterprises 10.12.2025, 16:29 MSK
10.12.2025 16:30
Russian Stock Market (MOEX): Share prices of chemical enterprises 10.12.2025, 14:59 MSK
10.12.2025 15:00


RSS Terminal About company Contacts Ad on the site
Copyright (c) Oreanda-News | Тел.: +7 (495) 995-8221

In case of reprinting or quoting the hyperlink to the website of Oreanda-News agency is required.