On TechRepublic: 5 best features in Google Chrome
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto, News.com
Posted on ZDNet News: Jun 12, 2006 8:32:00 PM

A new worm that targets Yahoo e-mail users is on the loose, taking advantage of an JavaScript flaw, a security company has warned.

The Yamanner worm targets all versions of Yahoo Web-based mail except the latest beta version, Symantec said in an advisory released Monday.

At the time of the advisory, there was no patch for the vulnerability. But by later on Monday, Yahoo said it had come up with a fix for the flaw, which it said had affected very few of its customers.

"We have taken steps to resolve the issue and protect our users from further attacks of this worm. The solution has been automatically distributed to all Yahoo Mail customers, and requires no additional action on the part of the user," a Yahoo representative said.

Both Yahoo and Symantec are encouraging people to update the antivirus definitions on their PCs.

Yamanner arrives in a Yahoo mailbox bearing the subject header "New Graphic Site." Once the message is opened, the computer becomes infected and the worm spreads itself to people on the Yahoo e-mail contact list. The harvested e-mail addresses are also sent to a remote online server, which Symantec suspects may use the information for spam campaigns.

"The worm is taking a pretty novel approach," said Dean Turner, senior manager of Symantec Security Response. "It takes advantage of a JavaScript vulnerability, so the user doesn't even have to click on an attachment to get infected."

Yamanner exploits the Yahoo flaw by enabling the scripts that are embedded in HTML e-mails to be run by the user's Web browser.

The worm, which was spotted in the wild early this morning, has hit the remote server more than 100,000 times, forwarding Yahoo e-mail addresses harvested from unsuspecting users, Turner said.

Although the worm is spreading quickly, and no patch has been issued, Symantec is rating the threat a "2." The security vendor uses a 1-to-5 rating system, with "5" as its most severe category.

"Antivirus definitions have been released for it, and Yahoo is working on a patch, so we don't want to cry wolf," Turner said. "Although there is the potential the worm will affect a larger number of people, for now to raise it to another (higher) level would be inappropriate."

He added it is premature to predict whether this worm will morph into other forms and attack other browser-based forms of e-mail, such as Google's Gmail.

Systems affected include Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003 and Windows XP, according to Symantec's advisory.

  • Talkback
  • Most Recent of 30 Talkback(s)
I opened that email a few days ago help
There isn't anything you need to do now. Yahoo will patch the problem soon. I would suggest that you never keep email addresses in an email provider address book. Keep it out of all Web related for... (Read the rest)
Posted by: DJnRF Posted on: 06/18/06 You are currently: Logged In | Log out
Well doesn't that Linux User 147560   | 06/12/06
just suck! uM0p ap!sdn   | 06/12/06
Linux and Mac are very boring cuberantcamper   | 06/12/06
ROTFLMAO!! HypnoToad   | 06/12/06
Life is good... KTLA   | 06/12/06
Message has been deleted. Southern.Pride   | 06/12/06
Message has been deleted. Linux User 147560   | 06/12/06
Story is very weak mobrien_12@...   | 06/12/06
that was going to be my point alandee4   | 06/13/06
question - and comment CobraA1   | 06/12/06
Wormy OS whisperycat   | 06/13/06
Or you can open it on a MAC and get a Trojan AlexiCyn   | 06/13/06
As is the case Shelendrea   | 06/13/06
So in other words, pay for it, then don't use it whisperycat   | 06/13/06
Huh? Shelendrea   | 06/13/06
I Love My Mac tomonroad   | 06/13/06
Only a matter of time until... BlazeEagle   | 06/14/06
Unpopular Macs webservant2003@...   | 06/14/06
yahoo virus jan133   | 06/13/06
yahoo worm is each yahoo user's own fault... dszakacs   | 06/13/06
Virus: Home or Business NancyVickersTier   | 06/13/06
Spam Mail is a JOKE NancyVickersTier   | 06/13/06
I'm sorry... MageOfChaos   | 06/13/06
I opened that email a few days ago help nazibarbie88   | 06/14/06
I opened that email a few days ago help DJnRF   | 06/18/06
This has run rampant through YahooGroups WiccaMagick   | 06/14/06
It really hit the innocents jmcbreen@...   | 06/15/06
Solution if you are infected WiccaMagick   | 06/14/06
Yahoo probably started the worm! LOL kjguillemette   | 06/14/06
One man blog site btljooz   | 06/14/06

What do you think?

advertisement
Click Here