Full Disclosure mailing list archives

Re: yahoo mail image verification


From: Eduardo Tongson <propolice () gmail com>
Date: Mon, 7 Feb 2005 23:17:19 +0800

On Mon, 07 Feb 2005 12:18:34 +0100, Thierry Haven
<thierry.haven () xmcopartners com> wrote:
After testing the French Yahoo portal, it appears that this flaw
actually exists. Let's hope they'll fix it soon. However, the impact of
a bruteforce attempt is minimal if you have a strong password by default
...

I've submitted this bug to Yahoo for review.


confirmed.
works with login.yahoo.com

-- 
Eduardo Tongson
http://i.keepsilent.net [:] GPG KeyID : 0x6033AC66
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x6033AC66
Key fingerprint : 0A86 79BA 3EC1 4B34 0D65  0E05 F9EC 98A2 6033 AC66
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: