Security Management
Published on Security Management (http://www.securitymanagement.com)
Yahoo Fixes Security Vulnerability
By John Wagley
Created 07/17/2012 - 21:38



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
Yes
Date: 
07/18/2012
By Line: 
By John Wagley
Teaser: 

Yahoo says it has fixed a security vulnerability that allowed hackers to obtain and expose online about 450,000 user names and passwords.

Yahoo has fixed a security vulnerability that allowed hackers to obtain and expose online about 450,000 user names and passwords, according to a company blog post [1] Friday.

The company had acknowledged the breach, which affected users of a service called the Yahoo Contributor Network, earlier in the week.

The hacked credentials were part of a “standalone file” containing Contributor Network credentials [2] from before May 2010, when Yahoo purchased the company, according to Yahoo. The Network pays contributors modest sums to generate search engine-optimized content. Credentials in the file were “not used to grant access to Yahoo systems and services.”

Yahoo also said it has deployed additional security measures for affected users and strengthened its underlying security controls [3]. It is also in the process of notifying affected users, and said it plans to continue to take “significant measures” to protect users and their data. Yahoo recommends that Contributor Network account holders change their sign-on information if they have not done so since before May 2010.

A hacking group called D33Ds Company [4] has taken responsibility for the hack.


photo by cogdogblog/flickr [5]

 

Related Resources: 
Thumbnail: 

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 38,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters, 1625 Prince Street, Alexandria, Virginia 22314-2818 U.S.A.
703.519.6200 | fax 703.519.6299 | www.asisonline.org

ASIS

© 2013 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/yahoo-fixes-security-vulnerability-0010086

Links:
[1] http://ycorpblog.com/2012/07/13/yahoo-0713201/
[2] http://www.securitymanagement.com/news/former-dhs-secretary-praises-new-government-cyber-identities-plan-008522
[3] http://www.securitymanagement.com/news/email-providers-move-toward-two-factor-authentication-008881
[4] http://contentequalsmoney.com/yahoo-voice-hacked-to-the-tune-of-450000-passwords/
[5] http://www.flickr.com/photos/cogdog/3736705040/