Skip to comments.
YAHOO! users being targeted by HACKER
FreeRepublic Exclusive ^
| Oct. 29, 2003
| Johnathan R. Galt
Posted on 10/29/2003 2:52:39 PM PST by JohnathanRGalt
click here to read article
Navigation: use the links below to view more comments.
first 1-20, 21-24 next last
To: JohnathanRGalt
Has this exploit been confirmed on all browsers, or is only Microsoft's Internet Explorer (IE) vulnerable? Do tell...
2
posted on
10/29/2003 2:58:27 PM PST
by
Prime Choice
(I want to be immortal. Then I'll never have to vote Democrat.)
To: JohnathanRGalt
I never click on those links anyway. Just tells them they have an active email account. Thanks for the warning. I have a yahoo account I use.
3
posted on
10/29/2003 3:00:55 PM PST
by
.38sw
To: JohnathanRGalt
Aha!. That is why my yahoo e-mail sucks and my hard drive was acting funky. Do you know a way out of this mess?
To: JohnathanRGalt
Yet another reason to not use Outlook, IE, or Windows. This isn't affecting any Yahoo users on Macs or Linux boxes...
5
posted on
10/29/2003 3:07:07 PM PST
by
Doug Loss
To: Doug Loss
Do you know this for a fact?
6
posted on
10/29/2003 3:10:33 PM PST
by
John W
To: John W
From the article: "Clicking on such a link triggers the well-known HTML overflow exploit, thereby crashing the users computer and perhaps messing up the data on his harddrive."
This is a Windows-only exploit; it doesn't affect non-Windows systems.
7
posted on
10/29/2003 3:25:10 PM PST
by
Doug Loss
To: JohnathanRGalt
SpamGuard has been improved just today, by my reckoning. You can report as message as spam and delete it with one click. I have been doing so. ZAPZAPZAP!!!
Death to Spam!
8
posted on
10/29/2003 3:28:39 PM PST
by
Ronin
(Qui docet discit!)
To: JohnathanRGalt
Thanks for the information. I was wondering why I have had so many more spam messages making their way into my Yahoo mail box lately. I never open mail I don't recognize and just trash it, but I took a look at what was in my trash folder and was surprised at how many seem to fit exactly the pattern you discribed.
9
posted on
10/29/2003 3:46:18 PM PST
by
Flying Circus
(As you do pray, so you do believe)
To: Ronin
SpamGuard has been improved just today, by my reckoning. You can report as message as spam and delete it with one click. I have been doing so. ZAPZAPZAP!!! and a different looking spam is sent next time -- and is delivered right to my inbox. SpamGuard fails to recognize it.
10
posted on
10/29/2003 5:33:15 PM PST
by
JohnathanRGalt
(---- Fight Islamist CyberTerror at: http://haganah.org.il/haganah/index.php ----)
To: Prime Choice
Has this exploit been confirmed on all browsers, or is only Microsoft's Internet Explorer (IE) vulnerable? Do tell... It's not just IE, I've confirmed the exploit on Netscape 7.1
11
posted on
10/29/2003 5:34:41 PM PST
by
JohnathanRGalt
(---- Fight Islamist CyberTerror at: http://haganah.org.il/haganah/index.php ----)
To: JohnathanRGalt
True, and I zap that one too. Unopened.
There is no relief in sight because the spammers are the warhead and the SpamGuard is the armor.
12
posted on
10/29/2003 5:40:21 PM PST
by
Ronin
(Qui docet discit!)
To: JohnathanRGalt
This sounds really stupid to me. I don't know any specific details about the exploit, but I used to write data entry programs under COBOL, then Unix C and DOS, then VB. I never allowed any data that could harm the program. I always read and validated any stream of data one character at a time. I had plenty of horsepower to do this with 8088 CPUs. There's no excuse for data crashing a program.
13
posted on
10/29/2003 5:44:09 PM PST
by
js1138
To: John W; Doug Loss
Yet another reason to not use Outlook, IE, or Windows. This isn't affecting any Yahoo users on Macs or Linux boxes... This is a Windows-only exploit; it doesn't affect non-Windows systems.
No, Macs, Linux and other Unix boxes can be brought down with stack overflow exploits.
It's a programmer error in the browser code that parses the URL. The code parsing the URL does not check to see if the URL is longer than the buffer allocated for it.
If you'd like to find out if your particular box is suseptable I can forward you one of the evil emails and you can try clicking on the link.
14
posted on
10/29/2003 5:57:36 PM PST
by
JohnathanRGalt
(---- Fight Islamist CyberTerror at: http://haganah.org.il/haganah/index.php ----)
To: js1138
There's no excuse for data crashing a program. I agree.
Or is there any excuse for a program crash to bring down the entire operating system (as Macs used to do, and Windows still does).
15
posted on
10/29/2003 5:59:58 PM PST
by
JohnathanRGalt
(---- Fight Islamist CyberTerror at: http://haganah.org.il/haganah/index.php ----)
To: Ronin
There is no relief in sight because the spammers are the warhead and the SpamGuard is the armor. I have to admit, for most other spam, SpamGuard works. Except for this particular (and dangerous) spam my inbox is usually free of spam.
I'm just saying there is a chink in the armor of SpamGuard. An evil hacker has found SpamGuard's Achilles heel.
After my first painful lesson, I now know enough not to click the URLs.
I just pity the fools (other Yahoo users) who have to go through what I did.
16
posted on
10/29/2003 6:11:25 PM PST
by
JohnathanRGalt
(---- Fight Islamist CyberTerror at: http://haganah.org.il/haganah/index.php ----)
To: unix; rdb3
sigh.... malicious web code is anything, but unusual.
To: JohnathanRGalt
It's been a long time since I saw a program bring down windows. Sometimes a hardware failure requires a restart, but I haven't rebooted windows for software issues since win2000 came along.
18
posted on
10/29/2003 6:17:03 PM PST
by
js1138
To: js1138
I haven't rebooted windows for software issues since win2000 came along. I'm on Windows 2000.
I wonder if the exploit will work on WinXP?
19
posted on
10/29/2003 6:22:28 PM PST
by
JohnathanRGalt
(---- Fight Islamist CyberTerror at: http://haganah.org.il/haganah/index.php ----)
To: JohnathanRGalt
Oh, I am sure that Yahoo will plug this hole, eventually. But by that time the evil geniuses who figured out this trick will have come out with something else.
It's a never-ending cycle.
20
posted on
10/29/2003 6:52:39 PM PST
by
Ronin
(Qui docet discit!)
Navigation: use the links below to view more comments.
first 1-20, 21-24 next last
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson