Results 1 to 3 of 3

Thread: Java script in yahoo mail

  1. #1
    Join Date
    Jan 2006
    Location
    At home
    Posts
    72
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default Java script in yahoo mail

    Somebody can help me with this issuse. I tried to send my own java script in yahoo mail but it doesn't work. how I can make them work???????

  2. #2
    Join Date
    Jun 2005
    Location
    英国
    Posts
    11,876
    Thanks
    1
    Thanked 180 Times in 172 Posts
    Blog Entries
    2

    Default

    I don't believe it's allowed in Yahoo, because of cross-site scripting issues.
    If you were to open an email containing malicious Javascript in your Yahoo account, that script could redirect you to a malicious site and transfer all your session cookies via GET variables. These cookies would include your Yahoo session ID, which a server-side script on the malicious host could then use to control your Yahoo account until your session expired, and possibly change the password on it to something the malicious site's owner could then use to log on (or perhaps not; it depends how Yahoo authenticates password changes).
    Twey | I understand English | 日本語が分かります | mi jimpe fi le jbobau | mi esperanton komprenas | je comprends franšais | entiendo espa˝ol | t˘i Ýt hiểu tiếng Việt | ich verstehe ein bisschen Deutsch | beware XHTML | common coding mistakes | tutorials | various stuff | argh PHP!

  3. #3
    Join Date
    Jan 2006
    Location
    At home
    Posts
    72
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    Oh I see thanks sir for clearing my facts!!!!!!!

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •