main
Report a problem

Yahoo fixes two flaws in mail system

malebolgia   on 20 August 2004 - 14:11 · 11 comments & 1044 views

Advertisement (Why?)
Today Yahoo fixed two serious security flaws in its popular e-mail system. Yahoo was alerted of these security problems towards the end of May and June. So why is it that Yahoo took such a long time to issue a solution?

Apparently Yahoo was able to fix the first security in a couple of days, while the other flaw took longer than expected. The first flaw allowed attackers to read a victim's browser cookies. The second flaw allowed the appearance of some pages to be altered. These "cross-site scripting flaws" are a relatively common issue in web application security, but that doesn't make them any less lethal. Unlike other flaws cross site scripting use server’s to attack client machines.

Cross site scripting flaws are really impressive (the way it uses a server to attack the client). By attacking the user this way tracking the one responsible becomes far more difficult. It's good to see that Yahoo has taken the proper steps to protect its users, and the best part is Yahoo users don't have to lift a finger. As all Yahoo had to do was fix its server code.

View: More Information

Post a comment · Send to friend Comments · There are 11 additional comments
(1 reply) #1 on 01 Jan 1970 - 00:00
#1.1 vetmalebolgia on 20 Aug 2004 - 16:34
Thanks [ timko ], a lot of time when I proof read my posts I’m in a hurry. I don't get as much time as I would have liked to. If I make a mistake in my posts just send me a PM and I'll fix it as soon as I can.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)