The Chief Technology Officer at security firm Imperva has revealed details about a potential weakness within the Yahoo Jobs website, which could have been exploited by cybercriminals to extract customer information. The Israel-based company discovered the vulnerability after monitoring discussions on a criminal forum and Yahoo was quick to plug the gap before serious data theft occurred.
Imperva’s Amichai Shulman outlined the basics of the issue, stating that in essence the hole could be exploited using a method similar to an SQL injection attack. In this case a technique known as blind SQLi would have been used to access personal details and financial information of thousands of Yahoo Jobs users. Continue reading