Personal tools
You are here: Home Newsletters NetCraft Mon, 27th Oct 2008

Mon, 27th Oct 2008

2.5

Ongoing Phishing Attack Exposes Yahoo Accounts

The Netcraft toolbar community has detected a vulnerability on a Yahoo website, which is currently being used to steal authentication cookies from Yahoo users — transmitting them to a website under the control of a remote attacker. With these stolen details, the attacker can gain access to his victims' Yahoo accounts, such as Yahoo Mail.

The attack exploits a cross-site scripting vulnerability on Yahoo's HotJobs site at hotjobs.yahoo.com, which currently allows the attacker to inject obfuscated JavaScript into the affected page. The script steals the authentication cookies that are sent for the yahoo.com domain and passes them to a different website in the United States, where the attacker is harvesting stolen authentication details.

When websites use cookies to handle authenticated sessions, it is extremely important to protect the cookie values and ensure they are not seen by other parties. Cross-site scripting vulnerabilities often allow these values to be accessed by an attacker and transmitted to a website under their control, which then allows the attacker to use the same cookie values to hijack their victim's session without needing to log in. This type of attack can be mitigated to some extent by using HttpOnly cookies to prevent scripts gaining access to the cookies — a feature that is now supported by most modern browsers.

Earlier this year, Netcraft blocked a similar flaw on another Yahoo website. The previous attack targeted a cross-site scripting vulnerability on Yahoo's ychat.help.yahoo.com site, which was served securely using a valid SSL certificate, adding further credibility to the attack. The attacker used the vulnerability to inject malign JavaScript into one of the site's webpages. Unlike the current attack, the injected code was sourced from a server in Spain, but also resulted in the victim's cookies being stolen and transmitted to a PHP script on the same server.

pula.js-resized.png
The small cookie-stealing script injected by the attacker.

hotjobs-yahoo-xss.png
A similar technique employed by the current attack.

In both cases, Netcraft found that the Yahoo cookies stolen by the attacker would have allowed him to hijack his victims' browser sessions, letting him gain access to all of their Yahoo Mail emails and any other account which uses cookies for the yahoo.com domain.

Simply visiting the malign URLs on yahoo.com can be enough for a victim to fall prey to the attacker, letting him steal the necessary session cookies to gain access to the victim's email — the victim does not even have to type in their username and password for the attacker to do this. Both attacks send the victim to a blank webpage, leaving them unlikely to realise that their own account has just been compromised.

ychat-resized.png
Both attacks send victims to a innocuous-looking, blank webpage.

The Netcraft Toolbar protects users against both of these attacks, warning that the malformed Yahoo URLs contain cross-site scripting elements, and that the URLs have been classified as known phishing sites.

Netcraft has informed Yahoo of the latest attack, although at the time of writing, the HotJobs vulnerability and the attacker's cookie harvesting script are both still present.

 
Posted by Paul Mutton at 01:21 PM UTC on Oct 26, 2008 in Security | Link to this article | RSS | Print Article
Linux Rackmount Server
For high quality performance Multi-core RAID servers at unbeatable prices with ongoing maintenance and support.
IT Support Bristol
IT Services and IT Support provider based in Bristol. Computer maintenance with server support as standard.
Mobile broadband
Compare mobile broadband deals and offers at the UK's best mobile broadband comparison site
Best Mobile Broadband Deals
Compare wireless mobile internet deals on Mobile Broadband Genie, the independent UK price comparison website.
IT Support
Award winning IT Support from help4IT, providing all the IT services of a dedicated IT department to businesses in London and the UK.
Call 0800 043 4448.
Introduction to Linux
Comprehensive 5 day introductory course in London, 8-12 March/10-14 May. Covers installation, command-line, Gnome, power tools, Shell scripting, Office Applications and more.
Broadband Packages
Compare broadband packages in your area with Broadband Choices, the UK's leading Ofcom-accredited broadband comparison calculator
IT Support Bristol
Netzen provide business IT Support for London, Bristol & Bath, Supporting Microsoft, Cisco, Linux & Mac
IT Support
For The Best IT Support In London Make Our IT Department Your IT Department. Microsoft Gold Certified Partner.
Rugs
Rugstore North East is the largest stockist of high quality modern and traditional rugs in the North East and provides great value and service to customers throughout the UK.
IT Support London
IT Services and IT Support London and Microsoft Small Business Specialist.
IT Support London
Efficent IT Support & Hosted Services for SME businesses in and around greater London.
IT SERVICES
Award winning IT Services from London provider Wavex offering support, advice, and training
IT Outsourcing
A full range of services, from hosting, data recovery and day-to-day support through to Board-level IT advice through our virtual IT Director offering.
Data Recovery
Professional data recovery services