<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/css" media="screen" href="http://s2.wp.com/wp-content/themes/vip/newyorkobserver/stylesheets/rss.css"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Betabeat &#187; Yahoo Mail</title>
	<atom:link href="http://betabeat.com/tag/yahoo-mail/feed/" rel="self" type="application/rss+xml" />
	<link>http://betabeat.com</link>
	<description>Just another WordPress.com site</description>
	<lastBuildDate>Fri, 17 May 2013 22:08:05 +0000</lastBuildDate>
	<language></language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='betabeat.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Betabeat &#187; Yahoo Mail</title>
		<link>http://betabeat.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://betabeat.com/osd.xml" title="Betabeat" />
	<atom:link rel='hub' href='http://betabeat.com/?pushpress=hub'/>
		<item>
				
		<title>Just $700 Will Buy the Key to Stealing Any Yahoo Email Account</title>

		<comments>http://betabeat.com/2012/11/just-700-will-buy-the-key-to-stealing-any-yahoo-email-account/#comments</comments>
		<pubDate>Mon, 26 Nov 2012 17:45:19 -0400</pubDate>
					<link>http://betabeat.com/2012/11/just-700-will-buy-the-key-to-stealing-any-yahoo-email-account/</link>
			<dc:creator>Steve Huff</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=71562</guid>
		<description><![CDATA[<p><div id="attachment_43864" class="wp-caption alignleft" style="width: 220px"><a href="http://nyobetabeat.files.wordpress.com/2012/05/yahoogetty.jpg"><img class="size-full wp-image-43864" title="Yahoo Reportedly Considering Laying Off Hundreds" alt="" src="http://nyobetabeat.files.wordpress.com/2012/05/yahoogetty.jpg" height="134" width="210" /></a><p class="wp-caption-text">Yahoo! (Getty)</p></div></p>
<p>Security expert Brian Krebs dropped a bomb on Yahoo email users last week, though his warning was probably lost in the roar of stories about Black Friday fistfights. <a href="http://krebsonsecurity.com/2012/11/yahoo-email-stealing-exploit-fetches-700/">According to Mr. Krebs</a>, an Egyptian hacker using the screen name TheHell is selling a Yahoo Mail exploit that could allow an attacker to take over and control a victim's email and browser activity. TheHell is only charging $700 for the information.</p>
<p>TheHell uploaded a video demonstration to prove he was serious. Mr. Krebs reproduced the video, which you can watch below.<!--more--></p>
<p><span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='640' height='390' src='http://www.youtube.com/embed/iBXvebXo-F4?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span></p>
<p>According to Mr. Krebs, the hacker implied his $700 asking price was a bargain:</p>
<blockquote><p>"I'm selling Yahoo stored xss that steal Yahoo emails cookies and works on ALL browsers," wrote the vendor of this exploit, using the hacker handle 'TheHell.' "And you don’t need to bypass IE or Chrome xss filter as it do that itself because it’s stored xss. Prices around for such exploit is $1,100 – $1,500, while I offer it here for $700. Will sell only to trusted people cuz I don't want it to be patched soon!"</p></blockquote>
<p>Yahoo's security director, Ramses Martinez, told Mr. Krebs that fixing the exploit itself isn't too hard--the problem is finding the weak Yahoo URL that allows the hacker to take control.</p>
<p>"Once we figure out the offending URL," said Mr. Martinez, "we can have new code deployed in a few hours."</p>
<p>Mr. Krebs noted that Yahoo doesn't pay hackers who notify the company about vulnerabilities like this. Several other companies do, Mr. Krebs writes, "including <a href="http://krebsonsecurity.com/2011/12/bugs-money/" target="_blank">Facebook</a>, <a href="http://googleonlinesecurity.blogspot.com/2010/11/rewarding-web-application-security.html" target="_blank">Google</a>, <a href="https://www.mozilla.org/security/bug-bounty.html" target="_blank">Mozilla</a>, <a href="http://www.ccbill.com/developers/security/vulnerability-reward-program.php" target="_blank">CCBill</a> and <a href="http://piwik.org/security/" target="_blank">Piwik</a>."</p>
<p>As for ensuring you don't fall prey to such a hack, always engage extreme caution when opening emails containing links, especially if they come from unfamiliar sources. Like guys who call themselves TheHell, for instance.</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_43864" class="wp-caption alignleft" style="width: 220px"><a href="http://nyobetabeat.files.wordpress.com/2012/05/yahoogetty.jpg"><img class="size-full wp-image-43864" title="Yahoo Reportedly Considering Laying Off Hundreds" alt="" src="http://nyobetabeat.files.wordpress.com/2012/05/yahoogetty.jpg" height="134" width="210" /></a><p class="wp-caption-text">Yahoo! (Getty)</p></div></p>
<p>Security expert Brian Krebs dropped a bomb on Yahoo email users last week, though his warning was probably lost in the roar of stories about Black Friday fistfights. <a href="http://krebsonsecurity.com/2012/11/yahoo-email-stealing-exploit-fetches-700/">According to Mr. Krebs</a>, an Egyptian hacker using the screen name TheHell is selling a Yahoo Mail exploit that could allow an attacker to take over and control a victim's email and browser activity. TheHell is only charging $700 for the information.</p>
<p>TheHell uploaded a video demonstration to prove he was serious. Mr. Krebs reproduced the video, which you can watch below.<!--more--></p>
<p><span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='640' height='390' src='http://www.youtube.com/embed/iBXvebXo-F4?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span></p>
<p>According to Mr. Krebs, the hacker implied his $700 asking price was a bargain:</p>
<blockquote><p>"I'm selling Yahoo stored xss that steal Yahoo emails cookies and works on ALL browsers," wrote the vendor of this exploit, using the hacker handle 'TheHell.' "And you don’t need to bypass IE or Chrome xss filter as it do that itself because it’s stored xss. Prices around for such exploit is $1,100 – $1,500, while I offer it here for $700. Will sell only to trusted people cuz I don't want it to be patched soon!"</p></blockquote>
<p>Yahoo's security director, Ramses Martinez, told Mr. Krebs that fixing the exploit itself isn't too hard--the problem is finding the weak Yahoo URL that allows the hacker to take control.</p>
<p>"Once we figure out the offending URL," said Mr. Martinez, "we can have new code deployed in a few hours."</p>
<p>Mr. Krebs noted that Yahoo doesn't pay hackers who notify the company about vulnerabilities like this. Several other companies do, Mr. Krebs writes, "including <a href="http://krebsonsecurity.com/2011/12/bugs-money/" target="_blank">Facebook</a>, <a href="http://googleonlinesecurity.blogspot.com/2010/11/rewarding-web-application-security.html" target="_blank">Google</a>, <a href="https://www.mozilla.org/security/bug-bounty.html" target="_blank">Mozilla</a>, <a href="http://www.ccbill.com/developers/security/vulnerability-reward-program.php" target="_blank">CCBill</a> and <a href="http://piwik.org/security/" target="_blank">Piwik</a>."</p>
<p>As for ensuring you don't fall prey to such a hack, always engage extreme caution when opening emails containing links, especially if they come from unfamiliar sources. Like guys who call themselves TheHell, for instance.</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/11/just-700-will-buy-the-key-to-stealing-any-yahoo-email-account/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2012/05/yahoogetty.jpg?w=150" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2012/05/yahoogetty.jpg?w=150" medium="image">
			<media:title type="html">Yahoo Reportedly Considering Laying Off Hundreds</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/fbcc4cd66cd87f0c50c499fa9dad0c78?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ncohenobserver</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2012/05/yahoogetty.jpg" medium="image">
			<media:title type="html">Yahoo Reportedly Considering Laying Off Hundreds</media:title>
		</media:content>
	</item>
		<item>
				
		<title>Booting Up: Where Stanford Kids Learn to be Normals</title>

		<comments>http://betabeat.com/2012/11/microsoft-sinofsky-stanford-cs198-3d-printing-yahoo-mail-gmail-lockheed-martin-cyberattacks/#comments</comments>
		<pubDate>Tue, 13 Nov 2012 08:33:28 -0400</pubDate>
					<link>http://betabeat.com/2012/11/microsoft-sinofsky-stanford-cs198-3d-printing-yahoo-mail-gmail-lockheed-martin-cyberattacks/</link>
			<dc:creator>Kelly Faircloth</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=69928</guid>
		<description><![CDATA[<p><div id="attachment_67779" class="wp-caption alignleft" style="width: 250px"><a href="http://nyobetabeat.files.wordpress.com/2012/10/4767767304_ba6b87f27d.jpeg"><img class=" wp-image-67779 " title="Morning" alt="" src="http://nyobetabeat.files.wordpress.com/2012/10/4767767304_ba6b87f27d.jpeg?w=300" height="180" width="240" /></a><p class="wp-caption-text">Morning, sunshine! (Photo: flickr.com/photos/wordridden)</p></div></p>
<p>How do Stanford students get the human education they need to lead startups? Many of them take CS198, a program that teaches computer science TAs how to teach, but ends up being a crash course for future CEOs. [<a href="http://nymag.com/daily/intel/2012/11/stanford-class-that-is-taking-over-tech.html"><em>New York</em></a>]</p>
<p>Steven Sinofsky--the dude who spearheaded the newly released Windows 8--has decamped from Microsoft. That doesn't look bad <em>at all</em>, guys. [<a href="http://bits.blogs.nytimes.com/2012/11/12/windows-chief-sinofsky-leaving-microsoft/"><em>New York Times</em></a>]</p>
<p>Yahoo Mail is reportedly working on a Gmail-like redesign. Just don't expect that to attract any CIA directors to the product. [<a href="http://allthingsd.com/20121112/along-with-new-homepage-yahoo-also-set-to-launch-a-gmail-like-email-reboot-to-slow-gmail-gains/">AllThingsD</a>]</p>
<p>"The advent of 3D printers shows that technology continues to exceed the limits of gun control." That's a comment from a pro-gun group, by the way. [<a href="http://animalnewyork.com/2012/3d-printed-guns/">Animal New York</a>]</p>
<p>Lockheen Martin--the top supplier to the Pentagon--has seen a sharp upswing in the rate of cyberattacks. [<a href="http://www.reuters.com/article/2012/11/13/net-us-lockheed-cyber-idUSBRE8AC02S20121113">Reuters</a>]</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_67779" class="wp-caption alignleft" style="width: 250px"><a href="http://nyobetabeat.files.wordpress.com/2012/10/4767767304_ba6b87f27d.jpeg"><img class=" wp-image-67779 " title="Morning" alt="" src="http://nyobetabeat.files.wordpress.com/2012/10/4767767304_ba6b87f27d.jpeg?w=300" height="180" width="240" /></a><p class="wp-caption-text">Morning, sunshine! (Photo: flickr.com/photos/wordridden)</p></div></p>
<p>How do Stanford students get the human education they need to lead startups? Many of them take CS198, a program that teaches computer science TAs how to teach, but ends up being a crash course for future CEOs. [<a href="http://nymag.com/daily/intel/2012/11/stanford-class-that-is-taking-over-tech.html"><em>New York</em></a>]</p>
<p>Steven Sinofsky--the dude who spearheaded the newly released Windows 8--has decamped from Microsoft. That doesn't look bad <em>at all</em>, guys. [<a href="http://bits.blogs.nytimes.com/2012/11/12/windows-chief-sinofsky-leaving-microsoft/"><em>New York Times</em></a>]</p>
<p>Yahoo Mail is reportedly working on a Gmail-like redesign. Just don't expect that to attract any CIA directors to the product. [<a href="http://allthingsd.com/20121112/along-with-new-homepage-yahoo-also-set-to-launch-a-gmail-like-email-reboot-to-slow-gmail-gains/">AllThingsD</a>]</p>
<p>"The advent of 3D printers shows that technology continues to exceed the limits of gun control." That's a comment from a pro-gun group, by the way. [<a href="http://animalnewyork.com/2012/3d-printed-guns/">Animal New York</a>]</p>
<p>Lockheen Martin--the top supplier to the Pentagon--has seen a sharp upswing in the rate of cyberattacks. [<a href="http://www.reuters.com/article/2012/11/13/net-us-lockheed-cyber-idUSBRE8AC02S20121113">Reuters</a>]</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/11/microsoft-sinofsky-stanford-cs198-3d-printing-yahoo-mail-gmail-lockheed-martin-cyberattacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2012/10/4767767304_ba6b87f27d.jpeg?w=150" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2012/10/4767767304_ba6b87f27d.jpeg?w=150" medium="image">
			<media:title type="html">Morning</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/0bbc75db8f7be0cab7d4698c7cd08df2?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kfairclothobserver</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2012/10/4767767304_ba6b87f27d.jpeg?w=300" medium="image">
			<media:title type="html">Morning</media:title>
		</media:content>
	</item>
	</channel>
</rss>
