Student and security researcher Robert Kugler has long warned Yahoo about vulnerabilities in its code, but the company seems to be ignoring him.
Kugler found that Yahoo has a vulnerability that allows attackers to redirect their victims to any website of their choosing, with a URL from the yahoo.com domain. The technique is called open redirection and helps scammers trick their victims into trusting the yahoo.com domain.
In a post, Kugler shows how the domain yahoo.com can redirect to google.com:
Although the end of the URL indicates that something might be wrong, it simply encodes the redirect URL, hiding its traces:
https://us.ard.yahoo.com/SIG=15n3q5c29/M=289534.11223993.11781333.10885343/D=he/S=18343859:FOOT2
Yahoo believes there is no vulnerability, although redirects are a favorite technique of phishers.
