This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Yahoo zero day exploit goes on sale for $700

by Alastair Stevenson

27 Nov 2012

View Comments

  • Tweet this
Yahoo campus sign

A hacker has begun selling what they claim is a zero-day exploit that will let criminals hijack control of Yahoo Mail users' accounts.

The hacker, who goes by the moniker TheHell, posted a video marketing a $700 exploit kit on the secretive Darkode cybercrime market on Monday. The video was later spotted and re-posted onto YouTube by security blogger Brian Krebs.

"I'm selling Yahoo stored xss that steal Yahoo emails cookies and works on ALL browsers. And you don't need to bypass IE or Chrome xss filter as it do that itself because it's stored xss," TheHell proclaimed in his marketing video.

"Prices around for such exploit is $1,100 - $1,500, while I offer it here for $700. Will sell only to trusted people cuz I don't want it to be patched soon"

The exploit infects users machines via a malicious email link and reportedly targets a cross-site scripting (XSS) weakness in Yahoo.com .

TheHell claimed that when clicked the malicious link exploits a cross-site scripting bug that lets criminals steal Yahoo Mail cookies. The cookies can then reportedly be used to log into and steal control of any compromised Yahoo mail account.

Krebs has reportedly informed Yahoo of the vulnerability, though at the time of publishing the company had not responded to V3's request for comment. 

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

17%

55%

10%

9%

9%

Popular Threads

Powered by Disqus
BlackBerry Q5

BlackBerry Q5 video demo

BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

PHP Developer - £30,000 - £35,000

PHP Developer £30,000 - £35,000 We are looking for...

Senior Project Manager - must speak fluent German

Massive is looking for a diligent, motivated, fluent...

Corporate Treasurer - Banking - London

Corporate Treasurer - Banking London - £70k-£120k...

Product Manager – Insurance (Telematics)

Product Manager – Insurance (Telematics) £40k-£50k...

To send to more than one email address, simply separate each address with a comma.