Comments on: Worm wriggles through Yahoo mail flaw
JavaScript flaw lets worm send itself to other Yahoo Web mail addresses when user merely opens the e-mail.
JavaScript flaw lets worm send itself to other Yahoo Web mail addresses when user merely opens the e-mail.
January 2, 2010 11:43 AM PST
January 2, 2010 9:41 AM PST
January 2, 2010 6:00 AM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
to blame for unnecessarily changing their Webmail system
to require Javascript.
Thanks
Sudhi
thanks and if anyone can advise any way of getting rid of this worm
thanks and if anyone can advise any way of getting rid of this worm
98, Windows Me, Windows NT, Windows Server 2003 and Windows
XP, according to Symantec's advisory."
Gee, what a surprise... yet another problem that does not affect
Macs! This makes one wonder why JavaScript seems to be getting
all the blame in this article. Could it be that the Microsoft operating
systems are at least partially to blame?!?
with it, it appears that Macs can be "carriers" for this thing. I
actually opened it, and everyone in my address book was sent
the email. The worm may not actually harm us Macers, but it still
opens with us...
We are not able to login. Worst part is we have forgotten the security question to reset our password and also our alternative email address are invalid as yahoo id were pretty much our identity for past 8-9 years. WE both have tons of confidential information in yahoo account. Is there a way we can talk to yahoo security or customer support team. We are genuine folks and not any spammers. We need our identity back. We need our nemesis back. Can any onehelp? I can be reached at 408 203 9960 or Sudhi.Seshachala@gmail.com
Thanks
Confidential information doesn't belong in a webmail account.
thanks
I cannot even get into Yahoo Groups anymore, they even have Yahoo Customer Care down.
As for the letter they emailed everyone? When and where?!?!
Take the MN Department of Public Safety. The code they use on there DMV site puts every DMV computer at risk of being exploited by this code. EVERY DVM PC.
There web code (MN DMV) requires the web code to use certain DNR printer templates that reside on the user's computer, not on a web server. So when someone from the MN DMV has to print out a DNR tag or any other orange tag for that matter the web code REQUIRES the need to access the printer templates on the local computer.
How does this put every MN DMV computer that uses this technology at risk? Well, say for instance a state employee decides to do there own surfing on lunch break ( I've personally seen this, so don't say it doesn't happen) and they come across a rogue website that uses JavaScript to access the local computer. You can figure out what can happen at this point. The security issues that this presents is just aw inspiring.
This would also allow TOTAL CONTROL of the host computer as well as the ability to download rogue code in the background unknown to the user until something terrible happens.
The solution for MN DMV:
Keep the template files on the web server for local web server access. You say there are so many people accessing the templates that it would decimate the performance of the servers! I tell you get a better IT staff, faster pipeline, and better servers. That will solve all of your problems. The MN DMV that is.
So you think that the MN DMV and Yahoo only have this problem you better check out your own web code. JavaScript is Super Powerful and part of the new Web 2.0 and AJAX era that's going on right now. So start practicing practical and safe coding!
Justin
Tech01.net
here's the problem I've been having:
yahoo won't let me sign in, I can use messenger but it just won't recognize my ID and password when I sign in to check mail for instance, it keeps taking me back to the sign in page,
furthermore it seems my cookies have been disabled as my bank page and amazon who have cookies asked me to re-sign.
it could be the worm, thought I don't remember clicking on it but with the amount of crap I get everyday, I may have clicked it by mistake.
if yahoo has indeed emailed a fix, how can I open the email if I can't sign in? also I tried singing in from another computer and I got the same response, it would keep reloading the sign in page
any help? thanks
- One man blog site does better
- by btl-jooz June 14, 2006 5:55 PM PDT
- job of reporting this issue than CNet.
- Like this Reply to this comment
-
(28 Comments)READ it HERE: http://p2pnet.net/story/9059