Cross Site Scripting: PoC in Yahoo Mail.

The attacking program could obtain your entire address-book, supplementing spammers’’ lucrative database of spam victims. And thanks to Yahoo’s recent integration of instant messaging within its web-mail site, it could also send instant messages to your friends impersonating you. (“You wanna do what to me?!”) Many of your online accounts would then become vulnerable as well, since the attacker would have access to your password-resetting emails; this potentially means access to your financial accounts. All other Yahoo services that you use are also at risk, including Yahoo Photos or Flickr. Read More>>

Related posts:

  1. Yahoo Mail integrates Paypal and Picnik
  2. YPOPs Provides You SMTP and POP Access to Yahoo Mail.
  3. Tutorial: Find IP Address of Sender in Yahoo Mail!
  4. [How-To] Send Emails with upto 100 MB Attachment from Yahoo Mail account
  5. Send Free SMS using Yahoo Mail

Leave a Reply