Share

No user data compromised, says Yahoo

Washington - Yahoo said some of its servers were breached briefly by hackers, but that the attack was unrelated to the newly discovered Shellshock vulnerability, and that no user data was compromised.

In a posting late Monday on the Hacker News forum, Yahoo's chief information security officer Alex Stamos said hackers managed to breach three of its sports servers that deliver live game-streaming data.

"After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock," Stamos wrote, referring to the recently discovered flaw which could affect millions of computers and other Internet-connected devices.

"At this time we have found no evidence that the attackers compromised any other machines or that any user data was affected. This flaw was specific to a small number of machines and has been fixed."

The comments came after security researcher Jonathan Hall reported the breach, and said it was the result of the flaw known as Shellshock or Bash. On Tuesday, Hall maintained that the attack was the result of a Shellshock attack.

"The Yahoo! infiltration WAS from the 'Shellshock' vulnerability... How do I know? Because I sat there watching it happen."

Stamos said the situation led to confusion because attackers had been trying to use the flaw to gain access.

"As you can imagine this episode caused some confusion in our team, since the servers in question had been successfully patched (twice!!) immediately after the Bash issue became public," he said.

"Once we ensured that the impacted servers were isolated from the network, we conducted a comprehensive trace of the attack code through our entire stack which revealed the root cause: not Shellshock."

The US government and technology experts warned last month of a vulnerability in some computer-operating systems, including Apple's Mac OS, which could allow widespread and serious attacks by hackers.

The flaw affects "Unix-based operating systems" powered by Linux and Apple's Mac OS. Apple recently said it created a patch for its operating systems, and other software firms have done the same.


We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.01
+0.2%
Rand - Pound
23.68
-0.1%
Rand - Euro
20.29
-0.4%
Rand - Aus dollar
12.24
-0.4%
Rand - Yen
0.12
-0.1%
Platinum
952.30
-2.4%
Palladium
1,036.00
+1.3%
Gold
2,371.75
-0.5%
Silver
28.27
+0.6%
Brent Crude
90.02
-0.1%
Top 40
66,899
0.0%
All Share
72,995
-0.0%
Resource 10
63,378
+2.8%
Industrial 25
97,824
-0.5%
Financial 15
15,384
-1.7%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders