<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Yahoo! redirects unleashed</title>
        <description>Copy/Paste from http://hackersblog.org article:

Yahoo redirects are and have been continuously used for spam, phishing and black SEO. Even though Yahoo is struggling to solve this problem, they are easy to find. When I say ease i mean seconds not minutes or hours.

The whole trick is to know how a patched link looks like. Its not hard at all.

All you need is:

Firefox

Link Gopher add-on

A search engine.

How does a link that can be used as for a redirect looks like?

http://us.ard.yahoo.com/SIG=15temu9ra/M=289534.6253107.7244481.6080815/D=classreal/S=750052198:FOOT/Y=YAHOO/EXP=1232849833/L=BmyXB86.ODX4VzI3SXtvrR9kVmjCm0l7r4kACp1e/B=NoaQBNj8a.0-/J=1232842633729605/K=pIWiCLQq81S96lmhwDqmiw--/A=2650127/R=2/SIG=11lp7krrc/*http://docs.yahoo.com/info/copyright/copyright.html

How does a link that can NOT be used as for a redirect to a site outside *.yahoo.com look like?  

http://rds.yahoo.com/_ylt=AkWscG8XXla3AoABf80g_WeHHwx.;_ylv=0/SIG=11idii63e/EXP=1232929280/**http%3A//hk.knowledge.yahoo.com/

How can we tell which link can be used?  

Notice this part of the link (from the first example): 

SIG=11lp7krrc/*http://docs.yahoo.com/info/copyright/copyright.html

After /* there follows the unaltered link to a diffrent domain. 

The second link is a bit diffrent.  

1232929280/**http%3A//hk.knowledge.yahoo.com/  

Don't mind the number of &amp;quot;stars&amp;quot;. This is what tells us that this redirect is useless: http%3A//.  

All links from redirect that start with http%3A// cannot be used for sites outside  yahoo.com. 

I can bet that there wont be more then a week from now (the moment of posting the article)  and this bug will be fixed cause we noticed a sudden love from Yahoo who is kind enough to pay us visits almost every day :)


// End of article //

Video demonstration: http://www.trilulilu.ro/hackersblog/b07ad9934d9738</description>
        <link>http://sla.ckers.org/forum/read.php?3,26259,26259#msg-26259</link>
        <lastBuildDate>Wed, 19 Jun 2013 19:32:50 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,26259,26357#msg-26357</guid>
            <title>Re: Yahoo! redirects unleashed</title>
            <link>http://sla.ckers.org/forum/read.php?3,26259,26357#msg-26357</link>
            <description><![CDATA[cool !]]></description>
            <dc:creator>xc0r3</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Fri, 30 Jan 2009 10:21:43 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,26259,26259#msg-26259</guid>
            <title>Yahoo! redirects unleashed</title>
            <link>http://sla.ckers.org/forum/read.php?3,26259,26259#msg-26259</link>
            <description><![CDATA[Copy/Paste from http://hackersblog.org article:<br />
<br />
Yahoo redirects are and have been continuously used for spam, phishing and black SEO. Even though Yahoo is struggling to solve this problem, they are easy to find. When I say ease i mean seconds not minutes or hours.<br />
<br />
The whole trick is to know how a patched link looks like. Its not hard at all.<br />
<br />
All you need is:<br />
<br />
Firefox<br />
<br />
Link Gopher add-on<br />
<br />
A search engine.<br />
<br />
How does a link that can be used as for a redirect looks like?<br />
<br />
<pre class="bbcode">http://us.ard.yahoo.com/SIG=15temu9ra/M=289534.6253107.7244481.6080815/D=classreal/S=750052198:FOOT/Y=YAHOO/EXP=1232849833/L=BmyXB86.ODX4VzI3SXtvrR9kVmjCm0l7r4kACp1e/B=NoaQBNj8a.0-/J=1232842633729605/K=pIWiCLQq81S96lmhwDqmiw--/A=2650127/R=2/SIG=11lp7krrc/*http://docs.yahoo.com/info/copyright/copyright.html</pre>
<br />
How does a link that can NOT be used as for a redirect to a site outside *.yahoo.com look like?  <br />
<br />
<pre class="bbcode">http://rds.yahoo.com/_ylt=AkWscG8XXla3AoABf80g_WeHHwx.;_ylv=0/SIG=11idii63e/EXP=1232929280/**http%3A//hk.knowledge.yahoo.com/</pre>
<br />
How can we tell which link can be used?  <br />
<br />
Notice this part of the link (from the first example): <br />
<br />
SIG=11lp7krrc/*<pre class="bbcode">http://docs.yahoo.com/info/copyright/copyright.html</pre>
<br />
After /* there follows the unaltered link to a diffrent domain. <br />
<br />
The second link is a bit diffrent.  <br />
<br />
1232929280/**http%3A//hk.knowledge.yahoo.com/  <br />
<br />
Don't mind the number of &quot;stars&quot;. This is what tells us that this redirect is useless: http%3A//.  <br />
<br />
All links from redirect that start with http%3A// cannot be used for sites outside  yahoo.com. <br />
<br />
I can bet that there wont be more then a week from now (the moment of posting the article)  and this bug will be fixed cause we noticed a sudden love from Yahoo who is kind enough to pay us visits almost every day :)<br />
<br />
<br />
// End of article //<br />
<br />
Video demonstration: http://www.trilulilu.ro/hackersblog/b07ad9934d9738]]></description>
            <dc:creator>2fingers</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sat, 24 Jan 2009 20:13:16 -0600</pubDate>
        </item>
    </channel>
</rss>
