D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Yahoo, was: Web based emails

 

On Sat, Oct 24, 2015 at 10:06:14PM +0300, Simon Waters wrote:
> One of the Yahoo email API issues was exploited by attackers using the index of
> address book contacts. So the address book wasn't directly leaked but they were
> still able to enumerate how many contacts you had and use them to add the
> element of "from someone I know" to the dodgy emails they sent.
> 
> E.g
> 
> Email this to address book entry 1, cc 2,3,4

Do you have a reference for this? It always looked like an API issue and
they had API issues in the past, but I haven't seen any such thing being
reported since we discussed them here after Mr Meowski's account, under
a previous name, had been spamming us.

Martijn.

Attachment: signature.asc
Description: Digital signature

-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq