Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How I stole the identity of every Yahoo user

Summary

How CRLF injection in Yahoo's fantasy-sports invite emails let attackers spoof and hijack messages: user-supplied names flowed into mail headers, opening identity spoofing across the platform.
Published
Collected

original ↗

Related coverage

back