[Full-disclosure] Yahoo url redirection flaw

insist kool insistkool at gmail.com
Fri Aug 3 18:00:48 BST 2007


Hi all,
Yahoo URL redirection flaw.


http://us.ard.yahoo.com/SIG=12hl6h3k3/M=572922.10815137.11567452.4937104/D=mail/S=150500152:MNW/Y=YAHOO/EXP=1186165822/A=4706278/R=1/SIG=12hiicv0n/*http://www.google.com/

Aditya K Sood has reported an extrememly similar bug two months ago (
http://archives.neohapsis.com/archives/fulldisclosure/2007-06/0438.html),
this is nothing new but still worthwhile to be aware.

Enjoy!

insistkool
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20070803/67d4dbd8/attachment.html 


Full-Disclosure is hosted and sponsored by Secunia.