Collected research
Yahoo Babelfish - Possible Frame Injection Attack - Design Stringency
Yahoo Babelfish - Possible Frame Injection Attack
Yahoo Babelfish translated any supplied URL with no referrer check and displayed no notice on the translated page, so arbitrary content could be loaded in an iframe inside the yahoo.com context. Removing the frame-busting code from a copy of the Yahoo login page yields a fake login form that inherits the domain's apparent trust and captures credentials.
Record
- Document
- Yahoo Babelfish - Possible Frame Injection Attack
- Researcher
- Aditya K Sood
- Published by
- zeroknock.blogspot.com
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .