WHID 2008-32: Yahoo HotJobs XSS

Attack Information
WHID ID: 
2008-32
Date Occured: 
26 Oct 2008
Attack Method: 
Outcome Information
Outcome: 
Target Information
Attacked Entity Field: 
Internet
Attacked Entity Geography: 
USA
Source Information
Attack Source Geography: 
USA

Netcraft reported an ongoing exploit of XSS vulnerability in Yahoo HotJobs site. The attackers have been using an obfuscated JavaScript to steal session cookies of victims, which were in turn sent to a server in the US.
The stolen cookie was a yahoo-wide cookie and therefore by stealing it the hackers could gain control of every service accessible to the victim within Yahoo, including Yahoo! Mail.
Netcraft identified the issue by observing irregular activity by its toolbar users and Yahoo! fixed the vulnerability short after, on Oct 28th.