Home

Keebler/Blog

« 24/Aqua Teen Hunger Force Mash-up
Hummingbird RedDot Summit 2007 »

Log-in to my blog with your Yahoo! account

Feel like logging into my blog with your Yahoo! account for no particular reason? Then please feel free to login here: https://login.yahoo.com/config/login?&.done=http://www.keebler.net. Don’t worry, I’m not stealing your password or anything; you’re using the real Yahoo!.

I’m been noticing lately how much information web developers applications are giving away in the query string. In this case I can’t really do anything besides redirect to my site, but holes like these make it really easy for phishers to look legit, and trick people into giving them personal information (or worse).

For example, what if you went to a URL starting with https://login.yahoo.com, entered your correct username/password, then we taken to another fake page, that looks just like the “Incorrect password” screen from Yahoo!, where you are asked for your username/password again. Would you really be sure to check the URL again? I think 99% of people would offer up their username/password to the hacker.

Anyhow, you get my point ;) Security good. Phishing bad. Yahoo! vulnerable. *grunt*

Yahoo Login Window

Related Posts

  • Yahoo! UI Library
  • Yahoo! Maps Beta
  • Unfortunate placement of Yahoo ad
  • Yahoo! Small Business Doesn’t Suck (well, kinda…)
  • So I buy a Last.fm account to …

This entry was posted on Saturday, February 10th, 2007 at 12:29 am and is filed under Security, Web Development. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply

Click here to cancel reply.

  • Blog Home

  • Tags

    90210 alessandra ambrosio animals asp.net audrina patridge battlestar galactica bikini bunny bush C# canada canada election ctv ctvglobemedia development Election Entertainment/Celebrity facebook Gordon Ramsay gorilla gossip girl hayden panettiere iphone last.fm liveblog liveblogging mesh08 muchmusic Music obama palin rachel bilson scribblelive shenae grimes subway telemarketers the hills the killers the office toronto ttc toronto tv us election video yeah yeah yeahs

    WP Cumulus Flash tag cloud by Roy Tanck requires Flash Player 9 or better.

  • Recent Posts

    • Trying to convince @idiotbante…
    • I wonder if the CTV “Save Loca…
    • Just finished dinner which I m…
    • I shouldn’t get as excited abo…
    • Stormtroopers’ 9/11 http://tin…
  • Categories

    • Election
    • Entertainment/Celebrity
    • Fake News
    • Featured
    • Funny
    • Keebler/Show
    • Music
    • My Releases
    • On-the-Road
    • RedDot
    • Reviews
    • Science/Technology
    • ScribbleLive
    • Security
    • Software
    • Torrent Live Stats
    • Tweets
    • Uncategorized
    • Web Development
  • Blogroll

    • Kitten-Monkey’s Cell
    • :: kattekylling ::
    • Adam Finley
    • blog-j
    • fuzzz.gaulin.ca
    • Idiot Banter
    • mad.greyarea.com
    • ob.blog
    • PollyPrissyPants
    • RedDot CMS Users Google Group
    • ScribbleLive Official Blog
  • My Sites

    • Flickr2Facebook
    • RedDot CMS
    • ScribbleLive
    • Where are my f(acebook)ing friends?
    • WhyYouShould