This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Yahoo Mail Worm Harvesting Addresses

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/wire/security/189400183
June 12, 2006
"A new worm targeting Yahoo's Web-based e-mail service bent on collecting addresses for a spam database has been spotted in the wild, a security company warned Monday. The "Yamanner" worm* exploits a JavaScript vulnerability in Yahoo's Web mail, Cupertino, Calif. security specialist Symantec said in a Monday morning warning to customers of its DeepSight Threat Management System. Yamanner is spreading, added Symantec, which has assigned the threat a "2" in its 1 through 5 rating system. The worm targets addresses with the "yahoo.com" and "yahoogroups.com" domains, and arrives as an HTML message containing JavaScript. As soon as the recipient views the message, the script automatically runs to spread the worm to other users in the Yahoo address book. The message will have a From" address of [removed] and a Subject: of "New Graphic Site". "Harvested addresses from the address book are then submitted to a remote URL, which is likely to be used for a spam database," noted Symantec in its alert. Yamanner won't execute on the newest Yahoo Mail Beta. Until Yahoo patches the flaw, Symantec recommended users steer clear of the service or disable the browser's JavaScript capabilities before reading any Web mail."

* http://www.sarc.com/avcenter/venc/data/[removed]

:(
FYI…

- http://isc.sans.org/diary.php?compare=1&storyid;=1398
Last Updated: 2006-06-12 19:40:36 UTC
"…It was first reported to the ISC at 12:32 UTC and now appears to be circulating in two slightly different variants… both variants are flawed therefore they spread very effectively but do not actually perform the intended action. The mass-mailer attempts to open a browser window… but a spelling mistake prevents this from working. The website appears to be dormant and rejecting accesses. The release of a new version barely two hours after we started our analysis which partially fixes the first version indicates that the code is very much under development and you should assume that the remaining bugs will be rapidly ironed out.
To activate the mass-mailer it is sufficient to open the mail message without clicking on the attachment and it will scour your address list and send itself as an attachment (forwarded message) to everyone on it. It searches for both @yahoo.com and @yahoogroups.com e-mail addresses. There is currently no trivial fix for Yahoo! mail as turning off Javascript on the browser will prevent you from reading your e-mail. For Yahoo! groups it is recommended that moderators/adminstrators turn off attachments for the time being to prevent this spreading further."

:ph34r:
Update:

- http://isc.sans.org/diary.php?compare=1&storyid;=1398
Last Updated: 2006-06-12 20:51:32 UTC …(Version: 4)
"…Yahoo! mass-mailer is currently making the rounds with a subject of "[random word] New Graphic site"… The mass-mailer also submits data to a page on av3.net but basic timing analysis on the response time seems to indicate that there is no difference between an access to the page without parameters or with the slew of parameters which are generated by the mass-mailer. This does not necessarily mean that the data is not being pharmed there and it is being investigated further… Note that this is not a binary attachment but a set of nested forwarded messages which are sent as an attachment in RFC2822 format… A long-term fix is apparently to migrate your Yahoo! e-mail to the Yahoo! Mail beta service although those who have already migrated mention that it is not a painless task…"

:( :ph34r:
Updated:

- http://www.sarc.com/avcenter/venc/data/[removed]
Last Updated on: June 13, 2006
"…technical details
JS.Yamanner@m performs the following actions:
1. Arrives on the compromised computer as an HTML email containing Javascript. The email may have the following characteristics:
From: Varies
Subject: New Graphic Site
Message body: Note: forwarded message attached.
2. Once the email is opened the worm exploits a vulnerability in the Yahoo email service to run a script.
3. Sends a copy of itself to certain email addresses gathered from the Yahoo email folders.
4. Targets email addresses from the @yahoo.com and @yahoogroups.com domains.
5. Contacts the following URL: [http://]www.av3.net/index.htm
6. Sends a list of email addresses gathered to the above URL…"

:ph34r: :ph34r:
FYI…

- http://news.yahoo.com/s/afp/20060613/ts_al…sitinternetworm
Tue Jun 13, 4:02 PM ET
"…Yahoo discovered a malicious software "worm" designed to borrow into its free e-mail service and has neutralized the threat, the US Internet search giant said. "Once we were aware of it we put a solution in place," said Kelly Podboy, a spokeswoman for the Mountain View, California, company. "It has been resolved. We don't know how many users were impacted, but we believe it was a very small fraction." An estimated 238 million people worldwide use Yahoo's free Web-based e-mail service, according to a recent industry analysis. The Yamanner worm was apparently tailored to target Yahoo Mail users, according to Podboy. Yahoo learned of the worm on Monday and automatically distributed a protective software modification that day, Podboy said. Yahoo advised its e-mail users to make sure they have updated anti-virus software on their computers and to block any incoming e-mail from sender "[removed]"…"

;)