Home > Security News > JavaScript worm spreads through Yahoo Mail
Security News:
EMAIL THIS LICENSING & REPRINTS

JavaScript worm spreads through Yahoo Mail

By Bill Brenner, Senior News Writer
13 Jun 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

A JavaScript worm is spreading via a security hole in Yahoo Mail, and end-users can become victims simply by viewing their email messages.

In an emailed advisory, Cupertino, Calif.-based AV giant Symantec Corp. said JS.Yamanner spreads through Yahoo email contacts when an end-user opens an email infected by the worm. The worm also sends these email addresses to a remote server on the Internet.

"This worm is a twist on the traditional mass-mailing worms that we have seen in recent years," Dave Cole, director at Symantec Security Response, said in a statement. "Unlike its predecessors, which would require the user to open an attachment in order to launch and propagate, JS.Yamanner makes use of a previously unknown security hole in the Yahoo Mail program in order to spread to other Yahoo users, and harvests user information for possible future attacks."

JS.Yamanner exploits a vulnerability that allows scripts embedded in HTML emails to be run by the user's browser. These scripts are normally blocked by Yahoo Mail for security reasons. Symantec has categorized JS.Yamanner as a Level 2 threat on a scale of one to five, with five being most severe.

Only those using contacts with an email address at @yahoo.com or @yahoogroups.com are threatened by this worm, Symantec said. Users of Yahoo Mail Beta don't appear to be affected.

The emails JS.Yamanner sends contains the following title and contents:

From: av3[at]yahoo.com
Subject: New Graphic Site
Body: this is test

Yahoo has reportedly released a fix for its standard and beta clients, and is working to block the malicious messages from its users' inboxes.

Michael Haisley, a handler with the Bethesda, Md.-based SANS Internet Storm Center (ISC), confirmed on the organization's Web site that the worm may spread without the user doing anything other than viewing a malicious email.

However, Haisley added that the worm could be readily modified to spread across many Web application systems that do not escape JavaScript when displaying data from a foreign source. "Many Web developers should reexamine their code," he said, "and make sure that display functions do not deliver potentially malicious code."

After testing several popular Web applications, ISC found that several are in fact vulnerable to the same type of exploit. Haisley said nearly any Web application could be affected, including bulletin boards, webmail programs, Web-based polls and any site that allows comments or uses guestbooks. "I even found one Web-based IRC client that didn't filter JavaScript, so a non-Web user could cause all Web users in a chat to perform some action.

The majority of these types of exploits cause little harm to users, Haisley said, but self-propogation could cause network congestion and generally make it more difficult to separate legitimate messages from malicious ones.

He said good coding practices, such as verifying that users are coming from an authorized form and that they are not submitting malicious code, can protect developers against this type of exploit.

Tags: Viruses, Worms and Other MalwareWeb Application Security (Also see Web Access Control)Mobile Code (Active X, JavaScript)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google




More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts