Culture and leisure


State


Industry


Transport


Science and engineering


Finances


Communication


IT, Media


Fuel and energy


Trade and Services


Physical activity


World


Русская версия


Login
✖
Loginor E-mail
Password
Remind password | Register
top news
.
S7 Airlines services included in the white list of Internet resources
.
Prices for new buildings in Russia will fall
.
Demand for business coaches has dropped in Russia
.
Putin appreciated the idea of postponing debt repayment by the regions
  • Oreanda-News.com
  • ›
  • Industry
  • ›
  • Yahoo email gets fix to nix sender-spoofing trickery
17.03.2016, 00:59

Yahoo email gets fix to nix sender-spoofing trickery

Industry
OREANDA-NEWS. March 17, 2016. The bug was discovered by independent researcher Lawrence Amer and published through Vulnerability Lab on Full Disclosure. On Monday, the security researcher released details of the flaw publicly, saying the sender-spoofing vulnerability affected the Yahoo webmail application.

Cyberattackers are able to remotely spoof the sender names of Yahoo email users through a vulnerability found within the "compose message" module of the Web service. A weakness in the system permits users to inject or intercept traffic in the POST/GET parameters, spoofing the email address to whatever sender name they wish.

This vulnerability is a problem as spoofed email addresses are often used in spear-phishing campaigns -- fraudulent emails sent for the purposes of information theft or to dupe victims into installing malware on their systems. If a user receives an email from a spoofed Yahoo address that seems legitimate, they may be more likely to fall for such a campaign.

The exploit is considered a medium severity issue, and the vulnerability has now been fixed. If you'd like, you can view the researcher's proof-of-concept video.

Yahoo was made aware of the flaw in October last year, and the Sunnyvale, California, company's developers were able to create a patch to fix the issue at the end of February. Amer submitted the email security flaw through Yahoo's Bug Bounty program, hosted on HackerOne. It's not known how much he earned for his work.

This story originally appeared at ZDNet under the headline "Yahoo patches sender spoofing email vulnerability."

Подпишитесь на каналы ИА "Ореанда-Новости":
VK News News


Материалы по теме:

The NATO country has flooded Russia with shoes16.04.2026 10:32:40

The EC has started borrowing to finance a loan to Ukraine27.04.2026 13:47:31

Другие новости:

Акинфеев записал обращение и сообщил, что не вернётся в состав ЦСКА21.04.2026 18:29:57

Бразильский боец ММА Пауло Коста заявил, что ненавидит русских10.04.2026 10:49:15

Share on social networks:
 Подписаться на наши группы: Instagram | VK | Facebook | Twitter


Rate this article:

Комментарии

Войти или зарегистрироваться.
Loginor E-mail
Password
Remind password | Register
Комментариев нет

НОВОСТИ ПАРТНЁРОВ



Latest news in section

The production of agricultural machinery in Russia has collapsed
23.04.2026 09:19
The NATO country has flooded Russia with shoes
16.04.2026 10:32
Russia plans to launch metal rolling in Cuba
09.04.2026 12:37
The Ministry of Agriculture told about sugar production in Russia
09.04.2026 06:05
Alrosa announced the potential of gold mining in four regions of Russia
07.04.2026 07:39
Russia and India are working on a project for the production of carbamide
03.04.2026 00:28
KAMAZ stands firmly on its feet and is developing, Putin said
31.03.2026 18:20
Rosneft has increased the share of water reuse
23.03.2026 12:41
The release of the updated flagship Aurus has begun in Yelabuga
11.03.2026 10:54
Wine production in Russia has collapsed
06.03.2026 09:32
KAMAZ will purchase Belarusian automotive components for another 540 million rubles
25.02.2026 14:17
Russian Stock Market (MOEX): Share prices of development enterprises 10.02.2026, 16:30 MSK
10.02.2026 16:30
Russian Stock Market (MOEX): Share prices of chemical enterprises 10.02.2026, 15:00 MSK
10.02.2026 15:00
Russian Stock Market (MOEX): Share prices of metallurgy and mining enterprises 10.02.2026, 12:29 MSK
10.02.2026 12:30
Russian Stock Market (MOEX): Share prices of development enterprises 09.02.2026, 16:29 MSK
09.02.2026 16:30
Russian Stock Market (MOEX): Share prices of chemical enterprises 09.02.2026, 14:59 MSK
09.02.2026 15:00
Russian Stock Market (MOEX): Share prices of metallurgy and mining enterprises 09.02.2026, 12:29 MSK
09.02.2026 12:30
Russian Stock Market (MOEX): Share prices of development enterprises 06.02.2026, 16:29 MSK
06.02.2026 16:30
Russian Stock Market (MOEX): Share prices of chemical enterprises 06.02.2026, 14:59 MSK
06.02.2026 15:00
Russian Stock Market (MOEX): Share prices of metallurgy and mining enterprises 06.02.2026, 12:29 MSK
06.02.2026 12:30
Russian Stock Market (MOEX): Share prices of development enterprises 05.02.2026, 16:29 MSK
05.02.2026 16:30
Russian Stock Market (MOEX): Share prices of chemical enterprises 05.02.2026, 14:59 MSK
05.02.2026 15:00
Russian Stock Market (MOEX): Share prices of metallurgy and mining enterprises 05.02.2026, 12:30 MSK
05.02.2026 12:30
RIA News: CBD has become the leader in the growth of wine production in Russia in 2025
23.01.2026 19:38
Russian Stock Market (MOEX): Share prices of development enterprises 23.01.2026, 16:29 MSK
23.01.2026 16:30


RSS Terminal About company Contacts Ad on the site
Copyright (c) Oreanda-News | Тел.: +7 (495) 995-8221

In case of reprinting or quoting the hyperlink to the website of Oreanda-News agency is required.