TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Dumping Yahoo authentication secrets with an out-of-bounds read

91 pointsby scarybeastabout 8 years ago

3 comments

smailiabout 8 years ago
For those wondering, this issue (referred to as YB2 or Yahoobleed #2 by the author) has <i>already been fixed</i> by Yahoo:<p>&gt; Yahoo! fixed YB2 at the same time as YB1, by retiring ImageMagick.
评论 #14380863 未加载
评论 #14382331 未加载
scarybeastabout 8 years ago
This is YB (Yahoobleed) #2. You might also enjoy YB #1: &quot;*bleed continues: 18 byte file, $14k bounty, for leaking private Yahoo! Mail images&quot;: <a href="https:&#x2F;&#x2F;scarybeastsecurity.blogspot.com&#x2F;2017&#x2F;05&#x2F;bleed-continues-18-byte-file-14k-bounty.html" rel="nofollow">https:&#x2F;&#x2F;scarybeastsecurity.blogspot.com&#x2F;2017&#x2F;05&#x2F;bleed-contin...</a>
mdaniabout 8 years ago
What is pointer visualization?
评论 #14382067 未加载
评论 #14381651 未加载