Behrouz Sadeghipour, a security researcher, has identified a critical vulnerability in one of Yahoo (hk.yahoo.net) that allowed him to access the admin panel.
It's funny to learn that hk.yahoo.net uses the word "admin" as the username and password for its administrative environment.
After gaining access to the admin panel, the researcher managed to upload a backdoor to the server. Using it, he was able to delete or create any file or execute commands on the server.
He was also able to control a few other Yahoo subdomains. After the researcher informed Yahoo , the company has fixed the security flaw.
The researcher is still waiting for his reward.
In addition to this bug, he also discovered another 'Directory Traversal attack' vulnerability in health.yahoo.com that allowed him to read the contents of the [/etc/passwd] files on the server.

