Web Hack List

Collected research

Yahoo Babelfish - Possible Frame Injection Attack - Design Stringency

Yahoo Babelfish - Possible Frame Injection Attack

Yahoo Babelfish translated any supplied URL with no referrer check and displayed no notice on the translated page, so arbitrary content could be loaded in an iframe inside the yahoo.com context. Removing the frame-busting code from a copy of the Yahoo login page yields a fake login form that inherits the domain's apparent trust and captures credentials.

Record

Document
Yahoo Babelfish - Possible Frame Injection Attack
Researcher
Aditya K Sood
Published by
zeroknock.blogspot.com
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .