Home > Domino News > JavaScript worm spreads through Yahoo Mail
Domino News:
EMAIL THIS

JavaScript worm spreads through Yahoo Mail

By Bill Brenner, Senior News Writer
14 Jun 2006 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

A JavaScript worm is spreading via a security hole in Yahoo Mail, and end-users can become victims simply by viewing their email messages.

In an emailed advisory, Cupertino, Calif.-based AV giant Symantec Corp. said JS.Yamanner spreads through Yahoo email contacts when an end-user opens an email infected by the worm. The worm also sends these email addresses to a remote server on the Internet.

"This worm is a twist on the traditional mass-mailing worms that we have seen in recent years," Dave Cole, director at Symantec Security Response, said in a statement. "Unlike its predecessors, which would require the user to open an attachment in order to launch and propagate, JS.Yamanner makes use of a previously unknown security hole in the Yahoo Mail program in order to spread to other Yahoo users, and harvests user information for possible future attacks."

JS.Yamanner exploits a vulnerability that allows scripts embedded in HTML emails to be run by the user's browser. These scripts are normally blocked by Yahoo Mail for security reasons. Symantec has categorized JS.Yamanner as a Level 2 threat on a scale of one to five, with five being most severe.

Only those using contacts with an email address at @yahoo.com or @yahoogroups.com are threatened by this worm, Symantec said. Users of Yahoo Mail Beta don't appear to be affected.

The emails JS.Yamanner sends contains the following title and contents:

From: av3[at]yahoo.com
Subject: New Graphic Site
Body: this is test

Yahoo has reportedly released a fix for its standard and beta clients, and is working to block the malicious messages from its users' inboxes.

Michael Haisley, a handler with the Bethesda, Md.-based SANS Internet Storm Center (ISC), confirmed on the organization's Web site that the worm may spread without the user doing anything other than viewing a malicious email.

However, Haisley added that the worm could be readily modified to spread across many Web application systems that do not escape JavaScript when displaying data from a foreign source. "Many Web developers should reexamine their code," he said, "and make sure that display functions do not deliver potentially malicious code."

After testing several popular Web applications, ISC found that several are in fact vulnerable to the same type of exploit. Haisley said nearly any Web application could be affected, including bulletin boards, webmail programs, Web-based polls and any site that allows comments or uses guestbooks. "I even found one Web-based IRC client that didn't filter JavaScript, so a non-Web user could cause all Web users in a chat to perform some action.

The majority of these types of exploits cause little harm to users, Haisley said, but self-propogation could cause network congestion and generally make it more difficult to separate legitimate messages from malicious ones.

He said good coding practices, such as verifying that users are coming from an authorized form and that they are not submitting malicious code, can protect developers against this type of exploit.

This article originally appeared on SearchSecurity.com.

Tags: IndustryLotus Notes Domino Antivirus Software and Virus ProtectionJavaScript for Lotus Notes DominoVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Industry
Lotus makes mobile partnerships and Notes Traveler top priorities
IBM Lotus to end Notes/Domino 7.x support
Are you ready for LotusLive hosted email services?
Getting ready for Lotusphere 2009
Managing and maintaining mobile devices on Lotus Notes Domino
Considerations for deploying mobile devices on Lotus Notes Domino
Admin2008: administrators and developers speak up
Developers mixed on direction of IBM Lotus R&D
IBM showcases Notes/Domino 8.5; new products at Lotusphere
Looking forward, IBM Lotus needs back-end improvements

Lotus Notes Domino Antivirus Software and Virus Protection
Protect Lotus Notes from malicious code with the Domino ECL
Online crime as ugly as ever
McAfee sued for patent infringement
Antivirus researcher Gullotto leaves Symantec for Microsoft
McAfee products vulnerable to code execution flaw
Symantec AntiVirus Corporate Edition vulnerable to flaw
Virus onslaught sickens smartphones
New Sober variant hits inboxes
Data shows spyware becoming 'global pandemic'
Alleged virus spreader held without bond

JavaScript for Lotus Notes Domino
Trap JavaScript runtime errors in Domino Web apps
JavaScript workaround fixes Lotus Notes 8.x PostOpen event issue
Write HTML and JavaScript in Notes view rows and columns on the Web
JavaScript detects Web browser type and version in Notes/Domino 8.0.2
JavaScript creates a jump box on a Lotus Notes Web form
Top 10 Lotus Notes/Domino coding and development tips of 2008
How to create dynamic JavaScript in Notes Domino without formulas
Trap an attachment path via the Domino file upload control field
Converting Lotus Notes views to XML documents using JavaScript
Mimic Lotus Notes Domino application functionality on the Web

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Lotus Notes Server Solutions - Quickr, Domino Server, Websphere
HomeTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersDomino IT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts