BLOG VIEW  |  HEADLINE VIEW
SUBMIT NEWS  |  RSS FEED  |  SEARCH

JavaScript Worm Targets Yahoo Mail Users

MONDAY JUNE 12 2006 9:19 AM

Submitted by WilWheaton. Edited By WilWheaton.

TAGS: yahoo, e-mail, security

Yahoo Mail users should not open any e-mails sent from av3@yahoo.com, according to Symantec, because simply viewing the e-mail will unleash a JavaScript worm that exploits an unpatched security hole in Yahoo's current mail software.

The JS-Yamanner worm spreads when a Windows user accesses Yahoo! Mail to open an email sent by the worm. The attack works because of a vulnerability in Yahoo! Mail that enables scripts embedded within HTML emails to be run within a user’s browser instead of being blocked.

Once executed, the worm forwards itself to an infected users' contacts on Yahoo! Mail. It also harvests these address and sends them to a remote internet server. Only contacts with an email address of either @yahoo.com or @yahoogroups.com are hit by this behaviour.

Infected emails commonly have the subject line "New Graphic Site" and are spoofed so as to appear from "av3@yahoo.com". Users who open infected emails will be redirected to a webpage at www.av3.net/index.htm.



It is important to note that, unlike previous worms which required the user to open an attachment, this worm exploits an unpatched security hole as soon as the e-mail is viewed.

Yahoo should move quickly to patch this hole, but until it is closed, Yahoo Mail users should block the address av3@yahoo.com.

 
zoton

zoton

Kuwait
November 2005

JUN 12, 2006 09:44 AM

anybody got the source code (interested)

nevabelle

nevabelle

HOPEFUL

I'm lost

JUN 13, 2006 06:21 PM

i opened this and was worried.

but then, i remembered, I HAVE A MAC


ahhh. excellent.


Food Coma: What The Fuck Is Ethnic Food?

Last Comment 44 MIN

That is what I was thinking. We are the hodgepodge bastard children of the world. More ...

The Frankenliberal

Last Comment 1 HR by bean

The Frankenliberal

Last Comment 1 HR

Look, I don't care who you support, if you're going to make generalized claims like that and expect to... More ...

Human Gaffe Machine

Last Comment 2 HR by hk85

Human Gaffe Machine

Last Comment 2 HR

Imagine that, a human being making a mistake, accepting responsibility, and apologizing. What an ass. More ...

Vampires: State of the Genre Report

Last Comment 6 HR

Well, not really unique (hasn't anything and everthing been done before?). I remember the idea of vampires... More ...

The King Orders You To Vote!

Last Comment 13 HR

As the King wills, so the world bends! Thine bidding shall be fulfilled! More ...

Palin: A Perfect Train Wreck

Last Comment 10/6/08 by Ferretbite

Palin: A Perfect Train Wreck

Last Comment 10/6/08

This really didn't fit anwhere else... (video) More ...

SuicideGirls Interview: Mister Cartoon:  Tattoo Entrepreneur
SuicideGirls Interview: Nikki Sixx
SuicideGirls Interview: On the Vineyard with Maynard James Keenan