Where you should disclose your vulnerabilities. Go read
RFPolicy if you want to do responsible disclosure, and go here for when all else fails.
Re: yahoo.com sql injection
Date: December 08, 2008 02:00PM
Heh.. I guess they're expanding their takeover bid.. now they want someone to take over their site, not just the company.
--thrill
---
It is not the degrees you hold, but the mind you possess. - thrill
Re: yahoo.com sql injection
Date: December 11, 2008 03:47PM
"The sad part is that Yahoo! didn’t adopt any policy whatsoever regarding this kind of problems. They dont admit they have a problem, nor do they give any credits to those who find them.
Following in the footsteps of other sites, Yahoo! could learn to gain from this. Vast majority of those who find bugs don’t disclose them anymore precisely for the fact that Yahoo! is in total denial."
Sounds right to me. I thought I was doing them a favor once by reporting some bugs, but they didn't take it seriously. That was 3.5 years ago and I bet they have bugs older than that.
Edited 1 time(s). Last edit at 12/11/2008 03:47PM by Robert Chapin.
Re: yahoo.com sql injection
Date: December 12, 2008 11:44AM
gr8 job dude !!!
SQL Injection is too cool and every big sites have this vuln :)
example : apple.com , yahoo.com , microsoft. ... ( exactly i don't remember what sub domain of it was ) and msn.com i think :-?
and ....
any way , again good job :)