Yet Another Bulletin Board
Sponsored by: The Fans!


Welcome, Guest. Please Login or Register.
Nov 24th, 2024, 8:37am

Upcoming Premiere Dates:
Survivor 23, Season premiere
Thursday, September 14 (8:00-9:30 PM, ET/PT) on CBS




Home Home Help Help Search Search Members Members Chat Chat Member Map Member Map Login Login Register Register

| Fantasy Survivor Game | Music Forums | The '80s Server Forums | Shop Online |



Metropolis Reality Forums « Worm Attacks Yahoo Email »

   Metropolis Reality Forums
   Off-Topic Forums
   In the News
(Moderators: lakelady, yesteach, MediaScribe, Bumper, Isle_be_back)
   Worm Attacks Yahoo Email
Previous topic | New Topic | Next topic »
Pages: 1  Reply Reply Add Poll Add Poll Notify of replies Notify of replies Send Topic Send Topic Print Print
   Author  Topic: Worm Attacks Yahoo Email  (Read 185 times)
yesteach
ForumsNet Administrator
USA 
*****






   
View Profile

Gender: female
Posts: 10465
Worm Attacks Yahoo Email
« on: Jun 12th, 2006, 7:10pm »
Quote Quote Modify Modify

Worm Attacks Yahoo E-Mail
 
Mass-mailing worm exploits a vulnerability in the Web-based e-mail, but its impact is low.
 
Jeremy Kirk, IDG News Service
Monday, June 12, 2006
 
A mass-mail worm that exploits a vulnerability in Yahoo's Web-based e-mail is making the rounds but the impact appears to be low, security vendor Symantec said today.    
 
The worm, which Symantec calls JS.Yamanner@m, is different from others in that a user merely has to open the e-mail to cause it to run, said Kevin Hogan, senior manager for Symantec Security Response. Mass-mail worms have usually been contained in an attachment with an e-mail note encouraging a user to open it.
 
The worm, written in JavaScript, takes advantage of a vulnerability that allows scripts embedded in HTML e-mail to run in the users' browsers. Yahoo users should be able to modify their settings to block the zero-day exploit, Hogan said.
 
Symantec rated the worm a Level 2 threat, one notch above its least harmful ranking. Hogan said the worm did not appear to be spreading widely, and he did not anticipate the threat level rising.
 
How It Spreads
 
When activated, the worms then sends itself to other users in the victim's address book who also use Yahoo e-mail with the suffixes of @yahoo.com or @yahoogroups.com. The worm mimics a function within Yahoo's Web mail called "Quickbuilder," which allows a user to add contacts in an address book from received e-mail, Hogan said. The process, however, is transparent to the victim, he said.
 
The harvested e-mail addresses are sent to a remote server. Users of Yahoo Mail Beta do not appear to be affected, Symantec said.
 
The worm also opens a browser that displays a Web page that does not appear to contain malicious content.
 
Although Yahoo's Web e-mail has not been fixed, users are advised to update virus and firewall definitions and block any e-mail sent from [email protected]. The subject line of the e-mail with the worm says "New Graphic Site," and the body says "this is test."
 
Yahoo officials could not immediately be reached for comment.
« Last Edit: Jun 12th, 2006, 7:11pm by yesteach » IP Logged

There are only 10 types of people in the world... those who understand binary, and those who don't.
Back to top
Pages: 1  Reply Reply Add Poll Add Poll Notify of replies Notify of replies Send Topic Send Topic Print Print

Previous topic | New Topic | Next topic »

Metropolis Reality Forums » Powered by YaBB 1 Gold - SP 1.3.1!
YaBB © 2000-2003. All Rights Reserved.