Уровень 0 · материалов: 6
В кластер входят документы об обнаруженных технических уязвимостях и ошибках в системах безопасности почтовых сервисов, но не входят материалы об общем качестве клиентской поддержки.
Общие признаки: критические ошибки безопасности, почтовые сервисы Yandex и Mail.ru, кража учетных данных, несанкционированный доступ к письмам и аккаунтам
Группа выше: Взломы и инциденты конкретных сервисов
Смысл: The main idea is to expose a severe security vulnerability in Yandex Mail where passwords for linked external email accounts were stored in plain text in the HTML source code and transmitted via unencrypted HTTP, allowing easy theft of credentials.
A security flaw in Yandex Mail allowed users to view plain-text passwords of linked external email accounts via the page source and network traffic.
Смысл: The text describes the discovery and exploitation of a critical authorization vulnerability in Yandex.Mail during a security contest. The author demonstrates how a failure to check user permissions in the 'nearest-messages' module could allow an attacker to read snippets of other users' emails on the same server node, and explains a method for targeting specific accounts.
A security researcher explains how a missing authorization check in a specific Yandex.Mail module allowed for the potential theft of emails through ID manipulation and node analysis.
Смысл: The main idea is to document a critical security flaw in Mail.ru's password recovery system where accounts without secret questions could be hijacked via the mobile interface.
A critical vulnerability in Mail.ru allowed attackers to change passwords of accounts without secret questions by using the mobile version of the recovery page.
Смысл: The main idea is that D33Ds Company stole and published 453,000 unencrypted Yahoo passwords using a SQL injection attack, exposing a major security failure by Yahoo.
Hacker group D33Ds Company leaked 453,000 unencrypted Yahoo passwords obtained via a union-based SQL injection attack.
Смысл: The main idea is that even with a complex password, a Gmail account can be compromised to send spam to a user's real contacts, emphasizing that password strength is not the only factor in account security.
A user reports their Gmail account was hacked and used to send spam links to contacts despite having a strong 14-character password.
Смысл: The main idea is a critical review of Mail.ru's account recovery process, illustrating how inefficient support and security flaws can lead to total loss of digital identity and linked assets.
The author shares a nightmare experience of failing to recover a Mail.ru account, leading to the compromise of other services and a recommendation to switch to Gmail.