Re: [Full-disclosure] Vunerability in yahoo webmail.

2006-06-14 Thread wac
Hi folks:Can I get this file somewhere else? Like a web site or something. This gmail thing detects it as a virus. I doub't yahoo will let it pass still, that's wht i don;t ask anyne to send it to me ;). I wonder who asked to have an stupid scanner in the e-mail that you can't disable. I don't

RE: [Full-disclosure] Vunerability in yahoo webmail.

2006-06-14 Thread php0t
Title: Message That doesn't work any more. Another one, for Internet Explorer however does work that i found the other day. Send yourself one using my POC :) http://zmailhost.ath.cx/ or http://zmail.zorro.hu/ php0t / zorro.hu -Original Message-From: [EMAIL PROTECTED]

[Full-disclosure] Vunerability in yahoo webmail.

2006-06-12 Thread David Loyall
Hello, all.I just received an email with an html attachment, on a yahoo account.When I opened the mail, yahoo automatically displayed the html, and executed the code within.What the hell. =)It forwarded the message to my contacts list, (or some other set of addresses, dunno,) and redirected my

Re: [Full-disclosure] Vunerability in yahoo webmail.

2006-06-12 Thread c0ntex
On 12/06/06, David Loyall [EMAIL PROTECTED] wrote: Oh, I've CC'd [EMAIL PROTECTED], but if someone else would give them a proper write-up, and encourage them to close the hole, that'd be wonderful. I know this guy who has over 7 years of direct security influence with Yahoo and Google security

Re: [Full-disclosure] Vunerability in yahoo webmail.

2006-06-12 Thread nocfed
On 6/12/06, c0ntex [EMAIL PROTECTED] wrote: On 12/06/06, David Loyall [EMAIL PROTECTED] wrote: Oh, I've CC'd [EMAIL PROTECTED], but if someone else would give them a proper write-up, and encourage them to close the hole, that'd be wonderful. I know this guy who has over 7 years of direct

Re: [Full-disclosure] Vunerability in yahoo webmail.

2006-06-12 Thread Eric Chien
Check out: http://securityresponse.symantec.com/avcenter/venc/data/[EMAIL PROTECTED]...Eric ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Vunerability in yahoo webmail.

2006-06-12 Thread pdp (architect)
They've got it quite quickly. 10x Since the source code is open to everyone now, it is just a matter of time for someone to redesign it and make it work Yahoo Beta as well. On 6/12/06, Eric Chien [EMAIL PROTECTED] wrote: Check out: http://securityresponse.symantec.com/avcenter/venc/data/[EMAIL

Re: [Full-disclosure] Vunerability in yahoo webmail.

2006-06-12 Thread n3td3v
Yahoo is under the control of hackers. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

RE: [Full-disclosure] Vunerability in yahoo webmail.

2006-06-12 Thread Sean Crawford
-Original Message- On Behalf Of n3td3v Sent: Tuesday, June 13, 2006 4:05 AM To: full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] Vunerability in yahoo webmail. Yahoo is under the control of hackers. Good, Yahoo are a pathetic service anyway so it's no big deal, hey

RE: [Full-disclosure] Vunerability in yahoo webmail.

2006-06-12 Thread php0t
Title: Message Oh, I've CC'd [EMAIL PROTECTED], but if someone else would give them a proper write-up, and encourage them to close the hole, that'd be wonderful. Since yahoo isn't known for fixing bugs fast unless it's serious (and even then), here's something i wrote up today. The

RE: [Full-disclosure] Vunerability in yahoo webmail.

2006-06-12 Thread php0t
-disclosure@lists.grok.org.ukSubject: RE: [Full-disclosure] Vunerability in yahoo webmail. Oh, I've CC'd [EMAIL PROTECTED], but if someone else would give them a proper write-up, and encourage them to close the hole, that'd be wonderful. Since yahoo isn't known for fixing bugs fast unless

Re: [Full-disclosure] Vunerability in yahoo webmail.

2006-06-12 Thread Cardoso
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of php0t p Sent: Tuesday, June 13, 2006 2:28 AM p To: full-disclosure@lists.grok.org.uk p Subject: RE: [Full-disclosure] Vunerability in yahoo webmail. p p p Oh, I've CC'd [EMAIL PROTECTED], but if someone