Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Re: yahoo mail image verification
From: Eduardo Tongson <propolice () gmail com>
Date: Mon, 7 Feb 2005 23:17:19 +0800

On Mon, 07 Feb 2005 12:18:34 +0100, Thierry Haven
<thierry.haven () xmcopartners com> wrote:
After testing the French Yahoo portal, it appears that this flaw
actually exists. Let's hope they'll fix it soon. However, the impact of
a bruteforce attempt is minimal if you have a strong password by default

I've submitted this bug to Yahoo for review.

works with login.yahoo.com

Eduardo Tongson
http://i.keepsilent.net [:] GPG KeyID : 0x6033AC66
Key fingerprint : 0A86 79BA 3EC1 4B34 0D65  0E05 F9EC 98A2 6033 AC66
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]