Yahoo, Hotmail Open to Attack
Again, or still, security flaws open your online mail accounts to exploits.
Quote:
The vulnerability was discovered in an Internet Explorer feature used to process extensions to HTML called HTML + TIME. The security hole could allow attackers to steal log-in and password information, or browse the contents of an e-mail account, according to an advisory released by GreyMagic Software.
Quote:
The company tested the vulnerability against Yahoo and Hotmail, but it could affect other e-mail services, GreyMagic said.
Quote:
Hotmail and Yahoo filter incoming HTML-format e-mail messages for malicious code. However, the filtering, combined with support for HTML + TIME, makes it possible to inject malicious script into incoming e-mail messages, GreyMagic said
They are using a flaw in IE, but I am wondering if other browsers could be exploited in the same way.
SOURSE