Sounds like "session hijacking". My understanding's somewhat limited never having tried it, but the idea is to trick the session state mechanism used by Yahoo via cookies. There's a book called "Web Attacks" that has a whole chapter on it. Or you might google it.
What you need to do is to clear out all your cookies, login to Yahoo mail, and then sign in using SSL. See if he's then able to pull the same trick.
If you use webmail, and I do, you should always be logging in via some secure mechanism or option. In Yahoo, you'll see a "Submits over SSL" link right below the sign in button. Log in via that link. In Hotmail, you'll see "Sign in using enhanced security" in their login box. I don't know about Gmail, haven't used their system. Webmail has some glaring security weakness, primarily cookies and also passwords being sent in the clear. It's not unusual to see passwords in packets that sniffers like Ethereal pick up.
Let me know if your associate is able to pull the same stunt when you've logged in securely. I'm curious to know the results. Thnx.
