A flaw in the way Web-based e-mail services Yahoo Mail and Hotmail filter messages left users open to attack via specially crafted online scripts, a security specialist said Tuesday.
The glitch created the possibility of attacks that could have let Web miscreants steal passwords, access the content of e-mail opened by victims or even spread worms through Web e-mail, said Lee Dagon, director of research and development for Israeli computer security firm GreyMagic Software. GreyMagic discovered the flaw March 6 and released an advisory about it Tuesday. "Hotmail and Yahoo do everything they can to prevent script from running in an e-mail message," Dagon said, readily filtering the Hypertext Markup Language content that arrives in messages. "We found a way to bypass their filters in order to make script run."
|