Vulnerability Development mailing list archives

Re: login yahoogroups.


From: Mr Slippery <slippery () theotherplane net>
Date: Sat, 22 Jun 2002 10:23:31 -0700

On Sat, Jun 22, 2002 at 09:23:10AM -0500, Alonso Caballero wrote:

My 'original' yahoo ID is: alabedsarc.  But i type... pay attention...

  alabedsarc{ 

And after typed my password, and... for my surprise... I log in
succesfully to my yahoo account;

Well, since Yahoo doesn't allow '{' in their usernames, I'm sure they
just strip them out before checking your password.  I suspect it won't
work if you append characters that they allow ([a-zA-Z0-9_], I think).

-slippery

--
Mr Slippery <slippery () theotherplanet net>


Current thread: