HomeSecurityThe use of "admin" as a username and password by...

Yahoo's use of "admin" as username and password leads to RCE

yahoo-shell

Behrouz Sadeghipour, a security researcher, has identified a critical vulnerability in one of Yahoo (hk.yahoo.net) that allowed him to access the admin panel.

It's funny to learn that hk.yahoo.net uses the word "admin" as the username and password for its administrative environment.

After gaining access to the admin panel, the researcher managed to upload a backdoor to the server. Using it, he was able to delete or create any file or execute commands on the server.

He was also able to control a few other Yahoo subdomains. After the researcher informed Yahoo , the company has fixed the security flaw.

The researcher is still waiting for his reward.

In addition to this bug, he also discovered another 'Directory Traversal attack' vulnerability in health.yahoo.com that allowed him to read the contents of the [/etc/passwd] files on the server.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS