12 Jun 2006

Yamanner Worm Hits Yahoo Today

, , ,

If you subscribe to any Yahoo Groups email lists, you have undoubtedly been hit today by numerous copies of a worm. I’ve seen about twenty copies this afternoon, all stopped by PC-cillin.

Information Week warns:

A new worm targeting Yahoo’s Web-based e-mail service bent on collecting addresses for a spam database has been spotted in the wild, a security company warned Monday.

The “Yamanner” worm exploits a JavaScript vulnerability in Yahoo’s Web mail, Cupertino, Calif. security specialist Symantec said in a Monday morning warning to customers of its DeepSight Threat Management System. Yamanner is spreading, added Symantec, which has assigned the threat a “2” in its 1 through 5 rating system.

The worm targets addresses with the “yahoo.com” and “yahoogroups.com” domains, and arrives as an HTML message containing JavaScript. As soon as the recipient views the message, the script automatically runs to spread the worm to other users in the Yahoo address book. The message will have a From” address of av3@yahoo.com and a Subject: of “New Graphic Site.”

“Harvested addresses from the address book are then submitted to a remote URL, which is likely to be used for a spam database,” noted Symantec in its alert.

StumbleUpon.com
Comments

Please Leave a Comment!




Please note: Comments may be moderated. It may take a while for them to show on the page.
















Feeds
Entries (RSS)
Comments (RSS)
Feed Shark