Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13
270 posts

Ultimate Geek


  #759404 11-Feb-2013 12:09
Send private message

From what I understand this isn't about passwords being compromised. Instead the XSS vulnerabilities grab a copy of the cookie Yahoo gives you when you log in (webmail, possibly other Yahoo services as well). Whoever or whatever presents Yahoo with that cookie is treated as you, until the cookie is invalidated (e.g. the time limit on the cookie expires, or you change your password).

As this has been going on with Yahoo worldwide for months, it is disappointing to see they still aren't on top of it. One XSS problem gets fixed, and the spammers find another one.

22878 posts

Uber Geek

Trusted
Lifetime subscriber

  #759406 11-Feb-2013 12:10
Send private message

sleemanj:
networkn:  Also each account is sending to all it's address book entries etc as well, which also couldn't happen via phishing.


While I'm not convinced that this is only the XSS phishing attack in play at all, it's not entirely correct to say that a phisher can't get your address book entries.  

I believe that the webmail by Yahoo/Xtra collects address book entries automatically, but in any case, the Yahoo XSS phishing hack from last month allows the attacker access to your webmail (by stealing your cookies) including the addressbook therein.

So yes, if this were the XSS phishing attack in use, they can (and would) send to your address book.



No I was saying that the act of Phishing (in and of itself) will not give them access to your address book. That isn't to say that same phisher couldn't gain access via other methods like the XSS (not phishing)

Phishing is the act of attempting to acquire information such as usernames, passwords, and credit card details (and sometimes, indirectly, money) by masquerading as a trustworthy entity in an electronic communication.


 
 
 
 


68 posts

Master Geek


  #759409 11-Feb-2013 12:21
Send private message

This whole situation seems odd - one of these emails was sent from an old address of mine and I received it as my current address is in the address book (I haven't used this address for over a year - and have never used the account for anything other than sending a couple of emails).

Telecom should really take a front foot approach and contact all users to get them to change their passwords (as opposed to being reactive).

22878 posts

Uber Geek

Trusted
Lifetime subscriber

  #759412 11-Feb-2013 12:27
Send private message

Tokes: This whole situation seems odd - one of these emails was sent from an old address of mine and I received it as my current address is in the address book (I haven't used this address for over a year - and have never used the account for anything other than sending a couple of emails).

Telecom should really take a front foot approach and contact all users to get them to change their passwords (as opposed to being reactive).


LOL any idea how long that would take ? They are the largest ISP in NZ!

16465 posts

Uber Geek


  #759422 11-Feb-2013 12:32
Send private message

networkn:
Tokes: This whole situation seems odd - one of these emails was sent from an old address of mine and I received it as my current address is in the address book (I haven't used this address for over a year - and have never used the account for anything other than sending a couple of emails).

Telecom should really take a front foot approach and contact all users to get them to change their passwords (as opposed to being reactive).


LOL any idea how long that would take ? They are the largest ISP in NZ!


An hour to write the email and send to their client database. They should force a password change when signing into Web mail.

22878 posts

Uber Geek

Trusted
Lifetime subscriber

  #759425 11-Feb-2013 12:35
Send private message

mattwnz:
networkn:
Tokes: This whole situation seems odd - one of these emails was sent from an old address of mine and I received it as my current address is in the address book (I haven't used this address for over a year - and have never used the account for anything other than sending a couple of emails).

Telecom should really take a front foot approach and contact all users to get them to change their passwords (as opposed to being reactive).


LOL any idea how long that would take ? They are the largest ISP in NZ!


An hour to write the email and send to their client database. They should force a password change when signing into Web mail.


Ok well I assumed (silly me) that he was suggesting calling. 

The requirement to change password is reasonable.


16465 posts

Uber Geek


  #759432 11-Feb-2013 12:36
Send private message

I got another this morning so the problem is still going on. The problem is that they haven't said what has caused it, apart from saying it was fixed.

 
 
 
 


BDFL - Memuneh
67768 posts

Uber Geek

Administrator
Trusted
Geekzone
Lifetime subscriber

  #759434 11-Feb-2013 12:43
Send private message

mattwnz: An hour to write the email and send to their client database. They should force a password change when signing into Web mail.


And those who never access the webmail would have no idea why their POP access stopped working, and there'd be a wave of calls to the help desk.

No, there must be another way.





 

 

These links are referral codes

 

Geekzone broadband switch | Eletricity comparison and switch | Hatch investment (NZ$ 10 bonus if NZ$100 deposited within 30 days) | Sharesies | Mighty Ape | Backblaze | Amazon | My technology disclosure 


16465 posts

Uber Geek


  #759446 11-Feb-2013 13:05
Send private message

freitasm:
mattwnz: An hour to write the email and send to their client database. They should force a password change when signing into Web mail.


And those who never access the webmail would have no idea why their POP access stopped working, and there'd be a wave of calls to the help desk.

No, there must be another way.



You can force a password change in some systems by allowing people to log in using their old password, and then they are forced to change that password after they login, before they can access their email. SOme online banks do this, so people regularly change their banking password.  Therefore it shouldn't affect pop access until the person has logged into webmail and changed the password.

BDFL - Memuneh
67768 posts

Uber Geek

Administrator
Trusted
Geekzone
Lifetime subscriber

  #759450 11-Feb-2013 13:10
Send private message

Which means people would still be vulnerable...





 

 

These links are referral codes

 

Geekzone broadband switch | Eletricity comparison and switch | Hatch investment (NZ$ 10 bonus if NZ$100 deposited within 30 days) | Sharesies | Mighty Ape | Backblaze | Amazon | My technology disclosure 


16465 posts

Uber Geek


  #759471 11-Feb-2013 13:21
Send private message

freitasm: Which means people would still be vulnerable...



Yes, but they are still vulnerable now anyway, until they change the password. This would at least make more people change their password. I would think that many people who use webmail probably have never changed their password in the past, nor the process of how to do it. A force password change on login would help, but if their is an exploit still then it probably will only be a short term help. But then again, I am not paid hundred of thousands or millions to work for telecom in this area, to work out a fix for the problem.


125 posts

Master Geek


  #759477 11-Feb-2013 13:32
Send private message

mattwnz:
freitasm:
mattwnz: An hour to write the email and send to their client database. They should force a password change when signing into Web mail.


And those who never access the webmail would have no idea why their POP access stopped working, and there'd be a wave of calls to the help desk.

No, there must be another way.



You can force a password change in some systems by allowing people to log in using their old password, and then they are forced to change that password after they login, before they can access their email. SOme online banks do this, so people regularly change their banking password.  Therefore it shouldn't affect pop access until the person has logged into webmail and changed the password.

I can give you the example that I pretty much have not used my Xtra account in over a year. I just have it on iOS as a mail account. Tell me in your scenario above, how that gets sorted?

360 posts

Ultimate Geek
Inactive user


  #759480 11-Feb-2013 13:36
Send private message

Just rang Telecom (philippines) to close my old Xtra account.  For anyone like myself who has an old account they don't use I'd recommend doing the same.  I don't use it and don't appreciate my old address book being hacked at the Yahoo servers and then being accused it is my fault.

It has been such a long sad service form Telecom/Yahoo.  They do seem to suite each other though.

Get yourself a domain name for $20/year and host your email where you like,  Google seems to be pretty reliable.

I am so glad that my last contact with Xtra has finally gone.  What a sad bunch they are.  I deal with many other email and hosting provider and not one is anywhere as bad as Xtra.

Sorry for the rant but when you get lied to by Xtra, as we all have been today, it's time to remind Xtra/Telecom of what a terrible dreadful poor service they offer and how customer don't appreciate being treated like fools.

2429 posts

Uber Geek

Trusted

  #759481 11-Feb-2013 13:37
Send private message

I just heard on the radio that Xtra has said its not their or Yahoo's faults its happening and they have nothing to do with it.

 (But you know the Media)

16465 posts

Uber Geek


  #759482 11-Feb-2013 13:37
Send private message

drquack32:
mattwnz:
freitasm:
mattwnz: An hour to write the email and send to their client database. They should force a password change when signing into Web mail.


And those who never access the webmail would have no idea why their POP access stopped working, and there'd be a wave of calls to the help desk.

No, there must be another way.



You can force a password change in some systems by allowing people to log in using their old password, and then they are forced to change that password after they login, before they can access their email. SOme online banks do this, so people regularly change their banking password.  Therefore it shouldn't affect pop access until the person has logged into webmail and changed the password.

I can give you the example that I pretty much have not used my Xtra account in over a year. I just have it on iOS as a mail account. Tell me in your scenario above, how that gets sorted?


Telecom would email your account to tell you about the problem, and to log into webmail and change your password. 
Those accounts that are inactive, and say haven't been used for 6 months, they should probably disable anyway, or automatically change the password on.

However apparently the exploit people have been talking about, is not the reason for the problem according to this story http://www.stuff.co.nz/technology/digital-living/8287236/Xtra-email-accounts-compromised

Quote -  Telecom said neither it nor its outsourced email provider YahooXtra were responsible for a massive malware attack on Kiwi internet users that began over the weekend.

1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13
View this topic in a long page with up to 500 replies per page Create new topic




News »

Freeview On Demand app launches on Sony Android TVs
Posted 6-Aug-2020 13:35


UFB hits more than one million connections
Posted 6-Aug-2020 09:42


D-Link A/NZ extends COVR Wi-Fi EasyMesh System series with new three-pack
Posted 4-Aug-2020 15:01


New Zealand software Rfider tracks coffee from Colombia all the way to New Zealand businesses
Posted 3-Aug-2020 10:35


Logitech G launches Pro X Wireless gaming headset
Posted 3-Aug-2020 10:21


Sony Alpha 7S III provides supreme imaging performance
Posted 3-Aug-2020 10:11


Sony introduces first CFexpress Type A memory card
Posted 3-Aug-2020 10:05


Marsello acquires Goody consolidating online and in-store marketing position
Posted 30-Jul-2020 16:26


Fonterra first major customer for Microsoft's New Zealand datacentre
Posted 30-Jul-2020 08:07


Everything we learnt at the IBM Cloud Forum 2020
Posted 29-Jul-2020 14:45


Dropbox launches native HelloSign workflow and data residency in Australia
Posted 29-Jul-2020 12:48


Spark launches 5G in Palmerston North
Posted 29-Jul-2020 09:50


Lenovo brings speed and smarter features to new 5G mobile gaming phone
Posted 28-Jul-2020 22:00


Withings raises $60 million to enable bridge between patients and healthcare
Posted 28-Jul-2020 21:51


QNAP integrates Catalyst Cloud Object Storage into Hybrid Backup solution
Posted 28-Jul-2020 21:40



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.