All the latest UK technology news, reviews and analysis


Yahoo zero day exploit goes on sale for $700

27 Nov 2012
Yahoo campus sign

It is currently unclear whether the exploit will work, though numerous security vendors, including Trend Micro security director Rik Ferguson, have indicated TheHell's claims could be legitimate.

"We discovered something very similar in Hotmail not too long ago," Ferguson told V3.

"How serious could it be? Well considering how interlinked our online services are, and how the email account is often at the heart of our web of existence it's like handing over the keys to your online identity."

F-Secure security researcher Sean Sullivan added that if legitimate, the exploit could prove the next hot item on the online black market.

"It certainly isn't a good thing that an active session cookie can be stolen or hijacked. But then, that's why I typically log off and purge my browser's cache at the end of the day. Also, it's why I ‘browse' with one browser (system default) and ‘logon' with another. I can see this type of attack being very useful for a select audience," Sullivan told V3.

Imperva chief technology officer Amichai Shulman highlighted the problem as systematic of wider problems within the security industry.

"The main issue here is not Yahoo specific but rather regarding such vulnerabilities as XSS - organisations should realise that we are living in a new era where the combination of good coding practices and network security is no longer good enough," said Shulman.

Automatic exploit kits have been a growing problem within the security industry. Earlier in the year both Microsoft and F-Secure have listed exploit kits like Blackhole as one of the biggest threats facing the globe.

  • Comment  
  • Tweet  
  • Google plus  
  • Facebook  
  • LinkedIn  
  • Stumble Upon  
Alastair Stevenson
About

Alastair has worked as a reporter covering security and mobile issues at V3 since March 2012. Before entering the field of journalism Alastair had worked in numerous industries as both a freelance copy writer and artist.

View Alastair's Google+ profile

More on Security
What do you think?
blog comments powered by Disqus
Poll

Windows 10 poll

What are your first impressions of Windows 10?
13%
4%
10%
4%
21%
4%
44%

Popular Threads

Powered by Disqus
V3 Sungard roundtable event - Cloud computing security reliability and scalability discussion

CIOs debate how to overhaul businesses for the digital era

V3 hosts roundtable with Sungard Availability Services

Updating your subscription status Loading
Newsletters

Get the latest news (daily or weekly) direct to your inbox with V3 newsletters.

newsletter sign-up button
hpv3may

Getting started with virtualisation

Virtualisation can help you reduce costs, improve application availability, and simplify IT
management. However, getting started can be challenging

ibmv3may

Converting big data and analytics insights into results

Successful leaders are infusing analytics throughout their organisations to drive smarter decisions, enable faster actions and optimise outcomes

.NET Developer

Calling all .NET Developers! My client, an award winning...

Java Technical Architect/Java Developer/Solution Architect-Agile,J2EE,

Java Technical Architect/Java Developer/Solution Architect...

SAP HR Payroll Consultant

SAP HR Payroll consultant - 3 Months - Immediate Start...

Frontend Developer Angular

After the start of two Frontend Developers, I am looking...
To send to more than one email address, simply separate each address with a comma.