Welcome Guest ( Log In | Register )

  Recent Software News
MSN Launches Web Messenger
Microsoft called top PDA software m...
Skype Makes Cell Calls Free
Windows Installer 3.0 Redistributab...
Mozilla Firefox 1.0 Released
  Recent Gaming News
Prince of Persia sequel goes gold
Nintendo Prepares Weekend Launch of...
Gamers get playing Half-Life 2
Halo 2 brings in $125 million for M...
Sims the Urbz Launches
  Recent Reviews
 · CoolerMaster Aerogate 3 A...
 · CoolerMaster AquaGate Wat...
 · OCZ Copper BGA Ramsinks
 · Mapower Warps Portable 3....
 · Vantec - PCI & RAM Slot P...
  Recent Forum Posts
Leadtek A350XT TDH and overclo...
FX5900U vs 9800Pro
Google Gmail Invites
Doom 3 SDK Released
Windows XP Sp2 Problems
  Announcement

Welcome to AusPCWorld - Australia's Leading PC Technology News & Reviews site.



> AusPCWorld > Tech News > Yahoo fixes two flaws in mail system






   
Yahoo fixes two flaws in mail system
Posted by Chris on 22 Aug 2004 - 13:20 0 comments
Previous Post | Tech News | Next Post
 
Today Yahoo fixed two serious security flaws in its popular e-mail system. Yahoo was alerted of these security problems towards the end of May and June. So why is it that Yahoo took such a long time to issue a solution?

Apparently Yahoo was able to fix the first security in a couple of days, while the other flaw took longer than expected. The first flaw allowed attackers to read a victim's browser cookies. The second flaw allowed the appearance of some pages to be altered. These "cross-site scripting flaws" are a relatively common issue in web application security, but that doesn't make them any less lethal. Unlike other flaws cross site scripting use server’s to attack client machines.

Cross site scripting flaws are really impressive (the way it uses a server to attack the client). By attacking the user this way tracking the one responsible becomes far more difficult. It's good to see that Yahoo has taken the proper steps to protect its users, and the best part is Yahoo users don't have to lift a finger. As all Yahoo had to do was fix its server code.

News source: News.com



There are 0 additional comments, Post a comment | View printable post | Open/Close All Comments


Add A new comment
Name: (Register)
Email: (optional)
Quick HTML: (help)
  Close current tag   Standard Mode
  Close all tags   Enhanced Mode
Comment:


Smilies
(help)
Parse URL's: (will automatically add [url] [/url] round the web addresses in your comment)