How I stole the identity of every Yahoo user
samcurry.net | blog | #bug-bounty | #email-security | #spoofing | #yahoo | #header-injection | #crlf-injection
Summary
How CRLF injection in Yahoo's fantasy-sports invite emails let attackers spoof and hijack messages: user-supplied names flowed into mail headers, opening identity spoofing across the platform.
- Published
- Collected
Skip to content