|
 |
 |
Yahoo leaks private key, allows anyone to build yahoo-signed chromeextensions by ferujkll sdff
 |
|
 |
Yahoo leaks private key, allows anyone to build yahoo-signed chromeextensions by FERUJKLL SDFF
|
 |
Article Posted: 04/29/2013 |
Article Views: 81 |
Articles Written: 2023 - MORE ARTICLES FROM THIS AUTHOR |
Word Count: 394 |
Article Votes: 0 |
|
Yahoo leaks private key, allows anyone to build yahoo-signed chromeextensions |
|
|
|
Business,Business News,Business Opportunities
|
 |
Yahoo was forced to release a new version of its Axis extension forGoogle Chrome after the original one contained a private key thatallowed anyone to digitally sign extensions in Yahoo's name. Axis is a new search and browsing tool from Yahoo that was released on Wednesday. It is available for desktop computers, as anextension for Google Chrome, Mozilla Firefox, Internet Explorer andSafari, as well as for iOS devices, as a stand-alone app. However, while looking at the source code for the Google ChromeAxis extension, hacker and security blogger Nik Cubrilovicdiscovered a serious security flaw -- the package included theprivate cryptographic key used by Yahoo to sign the extension.
"With access to the private certificate file [private key] amalicious attacker is able to create a forged extension that Chromewill authenticate as being from Yahoo," Nik Cubrilovic said in a blog post on Thursday. Google Chrome extensions come packed as CRX files, which areessentially digitally signed ZIP-format archives. Every CRX file contains a public key that's part of aprivate-public key pair unique to its creator. The private key isused to sign the extension, while the public key is used by thebrowser to verify the signature's authenticity.
Since private keys allow developers to digitally sign newextensions or update their old ones, they should always be keptsecret. In order to prove the implications of the private key leak,Cubrilovic created a proof-of-concept Chrome extension thatdisplays an alert on every visited website and signed it withYahoo's private key. An attacker can push a Yahoo-signed malicious extension to abrowser that has the Axis extension installed, by using techniqueslike DNS spoofing, Cubrilovic said. Google Chrome automatically checks for extension updates byquerying update URLs specified by developers.
If attackers canforge the DNS (domain name system) responses received by thebrowser, they can force it to install a rogue digitally signedextension update from a server under their control. Yahoo confirmed the security issue. "We worked quickly to resolvethe issue and have issued a new Chrome plug-in," a Yahoospokeswoman said via email. "Users who downloaded Yahoo! Axis onChrome between the hours of 6-9 p.m. Pacific Time on May 23, 2012,are encouraged to uninstall the previous version and reinstall thenew version at axis.yahoo.com.". I am Computer Cables writer, reports some information about garden arch gate , removable pool fence.
Related Articles -
garden arch gate, removable pool fence,
|
Rate This Article |
|
 |
|
Do you Agree or Disagree? Have a Comment? POST IT!
Reader Opinions |
|
 |
|
|
|
 |
 |
 |
Author Login |
|
 |
Advertiser Login
ADVERTISE HERE NOW!
Limited Time $60 Offer!
90 Days-1.5 Million Views

 |
 |
TIM FAY
After 60-plus years of living, I am just trying to pass down some of the information that I have lea...more
|
 |
 |
 |
 |
GENE MYERS
Author of four books and two screenplays; frequent magazine contributor. I have four other books "in...more
|
 |
 |
 |
 |
ADRIAN JOELE
I have been involved in nutrition and weight management for over 12 years and I like to share my kn...more
|
 |
 |
 |
 |
LAURA JEEVES
At LeadGenerators, we specialise in content-led Online Marketing Strategies for our clients in the t...more
|
 |
 |
 |
 |
MICHAEL BRESCIANI
Rev Bresciani is the author of two Christian books. One book is an important and concisely written b...more
|
 |
 |
 |
 |
STEPHEN BYE
Steve Bye is currently a fiction writer, who published his first novel, ‘Looking Forward Through the...more
|
 |
 |
 |
 |
LEVAL AINAH
I am an internet marketer and also an educator. My goal is to help others who are looking to improve...more
|
 |
 |
 |
 |
PAUL PHILIPS
For more articles, blog messages & videos and a free e-book download go to www.NewParadigm.ws your p...more
|
 |
 |
 |
 |
ALEX BELSEY
I am the editor of QUAY Magazine, a B2B publication based in the South West of the UK. I am also the...more
|
 |
 |
|