Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




fulldisclosure logo Full Disclosure mailing list archives

Re: yahoo mail image verification
From: Eduardo Tongson <propolice () gmail com>
Date: Mon, 7 Feb 2005 23:17:19 +0800

On Mon, 07 Feb 2005 12:18:34 +0100, Thierry Haven
<thierry.haven () xmcopartners com> wrote:
After testing the French Yahoo portal, it appears that this flaw
actually exists. Let's hope they'll fix it soon. However, the impact of
a bruteforce attempt is minimal if you have a strong password by default
...

I've submitted this bug to Yahoo for review.


confirmed.
works with login.yahoo.com

-- 
Eduardo Tongson
http://i.keepsilent.net [:] GPG KeyID : 0x6033AC66
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x6033AC66
Key fingerprint : 0A86 79BA 3EC1 4B34 0D65  0E05 F9EC 98A2 6033 AC66
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]