Yahoo says attackers looking for Shellshock found a different bug
Yahoo said Monday it has fixed a bug that was mistaken for the Shellshock flaw, but no user data was affected.
Three of the company’s servers with APIs (application programming interfaces) that provide live streaming for its Sports service “had malicious code executed on them this weekend by attackers looking for vulnerable Shellshock servers,” wrote Alex Stamos, Yahoo’s chief information security officer.
Stamos wrote on the Hacker News website that the servers had been patched after the Shellshock vulnerability was disclosed.
Yahoo was notified by Jonathan Hall, senior engineer and president of Future South Technologies, a security consulting firm. Hall wrote on his blog that he uncovered a vulnerability in at least two Yahoo servers.
To read this article in full or to leave a comment, please click here
leave a reply: