All the latest UK technology news, reviews and analysis


Yahoo zero day exploit goes on sale for $700

27 Nov 2012
Yahoo campus sign

A hacker has begun selling what they claim is a zero-day exploit that will let criminals hijack control of Yahoo Mail users' accounts.

The hacker, who goes by the moniker TheHell, posted a video marketing a $700 exploit kit on the secretive Darkode cybercrime market on Monday. The video was later spotted and re-posted onto YouTube by security blogger Brian Krebs.

"I'm selling Yahoo stored xss that steal Yahoo emails cookies and works on ALL browsers. And you don't need to bypass IE or Chrome xss filter as it do that itself because it's stored xss," TheHell proclaimed in his marketing video.

"Prices around for such exploit is $1,100 - $1,500, while I offer it here for $700. Will sell only to trusted people cuz I don't want it to be patched soon"

The exploit infects users machines via a malicious email link and reportedly targets a cross-site scripting (XSS) weakness in Yahoo.com .

TheHell claimed that when clicked the malicious link exploits a cross-site scripting bug that lets criminals steal Yahoo Mail cookies. The cookies can then reportedly be used to log into and steal control of any compromised Yahoo mail account.

Krebs has reportedly informed Yahoo of the vulnerability, though at the time of publishing the company had not responded to V3's request for comment. 

  • Comment  
  • Tweet  
  • Google plus  
  • Facebook  
  • LinkedIn  
  • Stumble Upon  
Alastair Stevenson
About

Alastair has worked as a reporter covering security and mobile issues at V3 since March 2012. Before entering the field of journalism Alastair had worked in numerous industries as both a freelance copy writer and artist.

View Alastair's Google+ profile

More on Security
What do you think?
blog comments powered by Disqus
Poll

BYOD vs CYOD vs BYOC poll

Which approach is your firm taking to managing employees' mobile devices?
20%
14%
5%
20%
29%
12%

Popular Threads

Powered by Disqus
Google Android logo

How to take a screenshot on Android

A step by step guide to how to screen-grab on a Google-powered smartphone

Updating your subscription status Loading
Newsletters

Get the latest news (daily or weekly) direct to your inbox with V3 newsletters.

newsletter sign-up button
hpv33

Data protection: the key challenges

Deduplication is a foundational technology for efficient backup and recovery

rdc2

iPad makes its mark in the enterprise

The iPad can become a supercharged unified communications endpoint, allowing users to enhance their productivity

Java Software Developer

Java Software Developer Location: Manchester, Lancashire...

3rd Line Windows Support - Exchange, VMware, Hyper V, Networ

3rd Line Windows Support - Exchange, VMware, Hyper V...

Oracle PLSQL Developer

Oracle PLSQL Developer - Livingston - Up to 40k Key...

Junior Oracle PLSQL Developer

Junior Oracle PLSQL Developer - Livingston - £25,000...
To send to more than one email address, simply separate each address with a comma.