Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> Yahoo Group Worm, Worm infecting Yahoo Group users through attachment.
mpinsky
post Jun 15 2006, 07:21 PM
Post #1


Member [ Level 1 ]
Group Icon

Group: Members
Posts: 41
Joined: 14-June 06
From: United States
Member No.: 13,934



Those of you who use Yahoo Groups may or may not have already heard this, but about three days ago, I received an update from one of the groups I am a member of. Inside this notice I found two "New Graphic Site" messages and one "Virus Warning". The previous two came with attachments. Luckily, I read the virus warning first before opening them. In the virus warning was this piece of advice:

QUOTE
Just a quick warning to members about a virus that is sweeping Yahoo groups. It contains a number of attachments and the subject line reads "New Graphic Site". Don't open the attachments - in fact, I'd suggest that the list owner/moderator delete them out of the list's archives (I've done that on my groups). Also, anyone who has received one of these - even if you didn't open it (my Outlook Express opens things automatically when I highlight the e-mail in my list - but, for once I'm happy I have a Mac, since I'm almost guaranteed to be safe from any viruses coming through) - run a virus scan on your computer.

Again, don't open any e-mails coming through Yahoo groups that have the subject "New Graphic Site" - it's a worm and will continue spreading through the groups more quickly as more members get their computers infected.

~Urd-chan


Just thought I'd give you guys a heads up if you haven't received this notice already.

This post has been edited by mpinsky: Jun 16 2006, 01:06 AM
Go to the top of the page
 
+Quote Post
sparx
post Jun 16 2006, 05:04 AM
Post #2


Premium Member
Group Icon

Group: Members
Posts: 243
Joined: 20-January 05
From: Bombay, INDIA
Member No.: 2,231



Outbreak Confirmed.

JS.Yamanner@m is a worm that is written in JavaScript. It exploits a vulnerability in the Yahoo! Mail service to send a copy of itself to other Yahoo! Mail contacts.

Notes:

* The worm cannot run on the newest version of Yahoo Mail Beta.


Also Known As: JS/Yamanner@MM [McAfee], JS_YAMANER.A [Trend Micro], Yamanner.A [F-Secure], JS/Yamann-A [Sophos]

Type: Worm
Infection Length: 6,377 bytes.



Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

Yahoo Mail users ae advised to BLOCK all mail from "av3@yahoo.com", although by now, Yahoo admins will have taken care of this server side. Also, use the new BETA GUI (in spite of its clunkish attempts to emulate GMail ;-) )

JS.Yamanner@m arrives on the compromised computer as a Yahoo! HTML email containing JavaScript. If the email is opened within Yahoo! Mail, it performs the following actions:

1. Exploits a vulnerability in the Yahoo! Mail service and executes a script.

2. Scans emails in the personal folders of the Yahoo! Mail account. The worm gathers email addresses that contain @yahoo.com and @yahoogroups.com domains.

Note: The personal folders are email folders in the currently logged in Yahoo! Mail account. These include folders such as the Inbox, Sent, and any custom-named folders in the account.

3. Sends a copy of itself to the email addresses gathered. The email may have the following characteristics:

From: Varies
Subject: New Graphic Site
Message Body: Note: forwarded message attached.

4. Redirects the Web browser from Yahoo! Mail to the following Web site:

[http://]www.av3.net/index.htm

5. Sends the list of gathered email addresses to the above URL.

This post has been edited by sparx: Jun 16 2006, 05:06 AM
Go to the top of the page
 
+Quote Post
finaldesign
post Jun 16 2006, 07:28 AM
Post #3


[+] Graphic Designer [+]
Group Icon

Group: Members
Posts: 614
Joined: 6-April 05
From: Croatia
Member No.: 3,666



No worrys for me, because I don't use yahoo groups. biggrin.gif
Go to the top of the page
 
+Quote Post
mpinsky
post Jun 17 2006, 02:11 AM
Post #4


Member [ Level 1 ]
Group Icon

Group: Members
Posts: 41
Joined: 14-June 06
From: United States
Member No.: 13,934



QUOTE(sparx @ Jun 16 2006, 01:04 AM) *

4. Redirects the Web browser from Yahoo! Mail to the following Web site:

[http://]www.av3.net/index.htm

5. Sends the list of gathered email addresses to the above URL.


So then the person at that website exploits those e-mail addresses?

This post has been edited by mpinsky: Jun 17 2006, 02:11 AM
Go to the top of the page
 
+Quote Post
sparx
post Jun 19 2006, 11:57 AM
Post #5


Premium Member
Group Icon

Group: Members
Posts: 243
Joined: 20-January 05
From: Bombay, INDIA
Member No.: 2,231



I can't really say what the person who receives the email addresses does with them, but it stands to reason that harvesting email addresses in any manner but particularly by way of a worm means the creator is up to no good!
Go to the top of the page
 
+Quote Post
tansqrx
post Jun 19 2006, 08:04 PM
Post #6


Super Member
Group Icon

Group: [HOSTED]
Posts: 533
Joined: 25-April 05
Member No.: 4,374



In a different article I heard that this exploit had something to do with AJAX. I have yet to find a good resource that fully describes the problem. Is the script run on the server or on the user’s end? It is slightly confusing as I have not heard that it only affects IE or Firefox and that is usually the deciding factor when a web exploit is run on the user’s machine.
Go to the top of the page
 
+Quote Post
yeh
post Jun 20 2006, 05:37 AM
Post #7


Advanced Member
Group Icon

Group: Members
Posts: 147
Joined: 13-May 06
Member No.: 13,389



I might be wrong here, so correct me if I am. I think what the worm does is when you open your mail, it would automatically mails itself to other people on your contacts. Does no harm to your computer, actually. I think it is run on the server and thus affects both IE and firefox.
Go to the top of the page
 
+Quote Post
sparx
post Jun 21 2006, 07:03 AM
Post #8


Premium Member
Group Icon

Group: Members
Posts: 243
Joined: 20-January 05
From: Bombay, INDIA
Member No.: 2,231



QUOTE(yeh @ Jun 20 2006, 11:07 AM) *

I might be wrong here, so correct me if I am. I think what the worm does is when you open your mail, it would automatically mails itself to other people on your contacts. Does no harm to your computer, actually. I think it is run on the server and thus affects both IE and firefox.


Quite correct. Although the worm does no harm to the local computer, it does take its toll on networks by clogging up bandwidth.What's scary is the fact that it's exploiting server-side JScript code to cause damage. All browsers are affected. This is NOT a browser issue, but an issue with Yahoo's implementation of scripting. Take note that this vulnerability does not exist for new BETA interface.
Go to the top of the page
 
+Quote Post

Fast ReplyReply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. To all Linux users(5)
  2. Have You Ever Been To Yagoohoogle?(15)
  3. Phishing In Myspace(8)
  4. Saint Michaels Sigs Group 11(2)
  5. Yahoo! Messenger Protocol Tutorial - Part 2(2)
  6. Finding Yahoo Account Creation Date(1)
  7. Yahoo Messenger 8.0(full)(3)
  8. New Windows Live Messenger 8.5 Beta!(13)
  9. Rate My Logo(7)
  10. Captchas + Yahoo! Chat = No Bots (for Now)(15)
  11. Yahoo! Messenger 9 Beta Preliminary Review(13)
  12. Do Google Search Better Than Yahoo?(15)
  13. Hacking Yahoo! Messenger(12)
  14. Microsoft To Buy Yahoo!(36)
  15. Optimize Your Site For Yahoo(1)
  1. Latest Yahoo! Vulnerability Appears To Be A Moving Target For Messenger(2)
  2. Who Uses A Yahoo E-mail(8)
  3. Letting Users Add Mysql Data With Php(1)
  4. What Mac's Do You Own?(11)
  5. Yahoo! Dodges The Bullet(4)
  6. Is The Sandbox Only For Google?(0)
  7. Yahoo! Messenger Talking To Google Talk?(7)
  8. Get Paid To Search Yahoo!(10)
  9. History Of Yahoo(2)
  10. Yahoo! Search Boss(5)
  11. Yahoo! Messenger Power User(1)
  12. Linux Partitioning Guide (new Users)(1)
  13. Yahoo! Messenger Challenge Response Algorithm(11)


 



- Lo-Fi Version Time is now: 11th October 2008 - 10:00 AM