Notices
The Basement Non-Honda/Acura discussion. Content should be tasteful and "primetime" safe.

Worm Attacks Yahoo E-Mail

Thread Tools
 
Old Jun 12, 2006 | 01:17 PM
  #1  
Grifter's Avatar
Grifter
Thread Starter
Senior Member
 
Joined: Dec 2000
Posts: 44,835
Likes: 0
From: the southwest
Default Worm Attacks Yahoo E-Mail

Jeremy Kirk, IDG News Service
Mon Jun 12, 11:00 AM ET



A mass-mail worm that exploits a vulnerability in Yahoo's Web-based e-mail is making the rounds but the impact appears to be low, security vendor Symantec said today.

ADVERTISEMENT

The worm, which Symantec calls JS.Yamanner@m, is different from others in that a user merely has to open the e-mail to cause it to run, said Kevin Hogan, senior manager for Symantec Security Response. Mass-mail worms have usually been contained in an attachment with an e-mail note encouraging a user to open it.


The worm, written in JavaScript, takes advantage of a vulnerability that allows scripts embedded in HTML e-mail to run in the users' browsers. Yahoo users should be able to modify their settings to block the zero-day exploit, Hogan said.


Symantec rated the worm a Level 2 threat, one notch above its least harmful ranking. Hogan said the worm did not appear to be spreading widely, and he did not anticipate the threat level rising.

How It Spreads

When activated, the worms then sends itself to other users in the victim's address book who also use Yahoo e-mail with the suffixes of @yahoo.com or @yahoogroups.com. The worm mimics a function within Yahoo's Web mail called "Quickbuilder," which allows a user to add contacts in an address book from received e-mail, Hogan said. The process, however, is transparent to the victim, he said.


The harvested e-mail addresses are sent to a remote server. Users of Yahoo Mail Beta do not appear to be affected, Symantec said.


The worm also opens a browser that displays a Web page that does not appear to contain malicious content.


Although Yahoo's Web e-mail has not been fixed, users are advised to update virus and firewall definitions and block any e-mail sent from av3@yahoo.com. The subject line of the e-mail with the worm says "New Graphic Site," and the body says "this is test."


Yahoo officials could not immediately be reached for comment.

http://news.yahoo.com/s/pcworld/2006...JlYmhvBHNlYwM-
Reply
Old Jun 12, 2006 | 02:19 PM
  #2  
JGordon's Avatar
JGordon
Senior Member
 
Joined: Mar 2002
Posts: 5,152
Likes: 0
From: Golden, CO
Default

Good thing I've had the "turn off display of html graphics" box checked since first making my yahoo account.
Reply
Old Jun 12, 2006 | 02:38 PM
  #3  
Brar's Avatar
Brar
|:]
 
Joined: Aug 2004
Posts: 14,182
Likes: 0
Default

I never open an email when I don't know who it's from h:
Reply
Old Jun 12, 2006 | 08:59 PM
  #4  
jaje's Avatar
jaje
HC Racer H5
 
Joined: May 2000
Posts: 4,261
Likes: 0
From: KCK
Default

i've got noscript extension in my browser so it will only run it when i give it permission
Reply




All times are GMT -8. The time now is 08:56 PM.