3 ms·
Already, two of my Facebook friends have reported they have been hit with this vulnerability.
by Simucal 14y ago
Already, two of my Facebook friends have reported they have been hit with this vulnerability.
- mrb 14y agoHow technical are your friends? Sometimes people think they have been "hacked" when their contacts receive spam with their name in the From: header. That is not the case at all. Spammers simply spoof the From:. No hack required. Beside, this XSS vulnerability is silent by nature. The victim has no idea and no visual indication that clicking a link ends up stealing his/her Yahoo auth cookies.
- Pr0 14y agoSure, but if the victim sends the same email to all of their friends, he or she will surely end up finding out.
- mrb 14y agoSpammers also have ways to determine your social circle (eg. scraping Facebook), so they can send mail to all your friends.
- LarrySDonald 14y agoDepends on how visible your name->email is. I got one yesterday to my current non-public email address (never used for anything except person to person email, and usually not even that), from the one guy I know who uses yahoo email. Told him he might want to make sure his AV is in shape and change his password. Still no idea if it's from this or something else, he discovered that he had a bit of malware (nothing extreme, your average user level) so it could have been anything, but the timing is pretty suspicious considering his setup has gotten infected exactly once over about the four years I've known him (that I know of, but I have no doubt I'd be the first to know).
- Simucal 14y agoThe two friends in question aren't very technical at all. They had reported, after being alerted by a friend, that their account had sent out emails posing as them and contained a malicious link. They confirmed this by checking their sent mail. So I think this is more than spoofed email. Plus, having both of these friends, with Yahoo accounts, report this on the same day of this vulnerability going public is a pretty big coincidence.