4 ms·
the gist of it seems to be that yahoo ran a vulnerable wordpress site that allowed the attacker to run javascript from the yahoo domain, allowing them to steal
by throwaway125 14y ago
the gist of it seems to be that yahoo ran a vulnerable wordpress site that allowed the attacker to run javascript from the yahoo domain, allowing them to steal login cookies.
That makes me wonder, doesn't yahoo set the http only flag for their session cookies? Is there any reason you may want javascript to access the session cookie?
Suppose it's a good time for everyone to verify that their websites properly set http only on any cookies you don't want to access via javascript.