Yahoo! 'sticky' security error after 1 day of launch
Yahoo! Many people were surprised when they suddenly launched their own web browser, called Axis yesterday. However, it seems that Yahoo! was too impatient in his decision when a serious security error was soon discovered in Axis.
>>>Yahoo launches Axis browser - Chrome's "killer"?
Axis is the web browser that Yahoo! launched as an application for iOS platform (both iPhone and iPad), and works as an add-on for browsers on personal computers (Firefox, Safari, Chrome and Internet Explorer).
However, according to a hacker and businessman, Nik Cubrilovic, the add-on Axis on Google's Google Chrome web browser contains a serious security hole.
After downloading and installing the Axis add-on for Google Chrome for the purpose of checking source code, Cubrilovic discovered that the validation license that Axis uses to authenticate with Google, is basically a code used for Chrome. Check if the add-on is safe to install, can be easily accessed by anyone.
Yahoo!It will take a lot of effort to regain user trust with Axis after a serious security error has been detected
This means that if a hacker wants to create a malware to infect Chrome, they can use this Axis authority to make the malware seem to be safe, aimed over the eyes. Chrome browser.
Once you have the right to confirm, Chrome will think that this malware has been approved by Yahoo! and allow installation.
Cubrilovic said he tested this security hole by creating a copy of the Axis add-on on Chrome, using the authentication license on the add-on Axis, then installing the fake add-on. Chrome browser. This process was perfect when Chrome mistook it for Yahoo's add-on.
According to Cubrilovic, if hackers use this Axis validation license, hackers could theoretically create malware to be able to capture all the websites that users access on Chrome browser, including login password and cookies.
As soon as there was information about this dangerous security vulnerability, a Yahoo spokesman said: 'We have received a report on Axis security vulnerability in Chrome. We will work quickly to fix this problem and launch new add-on on Chrome. Users who have installed Yahoo Axis on Chrome during the period of 6-9 am (Vietnam time) from May 23, please remove the old add-on and install the new version '.
Sophos later confirmed that Yahoo replaced the Axis add-on on Chrome browser to the new version. However, it is worrisome whether Google canceled the old license used by the old Axis add-on. If not, hackers can still take advantage of this license to create fake and intrusive add-ons to the Chrome browser.
Sophos also advises users not to use Axis at this time and wait a while for this add-on to really improve.
The newly discovered security vulnerability is considered a serious 'stumbling block' for Yahoo !, as it attempts to regain its image and reputation. However, with a serious security error after only one day of launch, Yahoo! It will take a lot of effort to regain the trust of users.
You should read it
- AMD CPUs also have security vulnerabilities that have existed for many years now!
- Modify the axis of the chart in Excel
- Google Chrome has a serious zero-day error, and hackers can execute malicious code at its fullest
- TorMoil vulnerability reveals true IP from Tor Browser
- Protect yourself against IE security holes
- Dynamics of Google, Apple and Microsoft when the browser has a security error
- The unsafe 'feature' on UC Browser allows hackers to take control of Android phones remotely
- 4 security warnings you should not 'ignore'
May be interested
- Serious security flaws on Windows 10 allow anyone to log in by voiceon windows 10, there is a new bug called open sesame (open), taking advantage of this error, hackers can use their own voice to execute code at any time on the computer.
- Google awarded US $ 36,000 to the Uruguayan boy who discovered the carrier's serious security errorrecently, google awarded $ 36,337 usd to ezequiel pereira, a uruguayan teenager because he discovered a serious security error that could be exploited by hackers to change the company's system.
- How to fix A20 Error when starting the computererror a20 error appears when the power on self test (post) process occurs automatically after the computer is started. the operating system is not loaded when this a20 error appears. the error message a20 error often appears in many ways, but usually: a20, error a20, a20 error.
- Twitter has a serious security error, asking users to change their password nowrecently, twitter has uploaded a tweet on its official account, asking users of this social network to change the password immediately to avoid the risk of information leakage due to a serious security error.
- Protect yourself against the Heartbleed security errorsecurity experts offer advice to help users protect themselves safe from the security hole heartbleed is spreading terror to the web world.
- How to add apps to launch with Windows 11when you add applications to launch with windows 11, it will help launch the application you need faster, simplifying the application opening process. and through the management interface in windows 11, you can also delete the application that launches with you if you want.
- Instagram has a serious security error with registration with Facebookthe error, this happens every day, every hour, as long as someone finds out (maybe a user, maybe an author, maybe a vandal - hacker), recently, a user he said he found instagram service existed with a serious security error stemming from registration.
- Fix 'The device is not ready' error when running the .exe file on Windows 10if when you try to open or launch any file with an .exe extension on the internal hard drive of a windows 10 pc and get the error message 'the device is not ready', then this article will help. for you.
- How to Fix the Application Error 0xc000007b Using AIO 210error 0xc000007b is an application error code on windows that appears when a program fails to launch or run. this is generally encountered when an application tries to open on a computer that's missing important components or runtime...
- 5 most common Windows errors and this is a fixhow many windows errors have you encountered when using a computer? it is frustrating to see error messages because they are often unclear and do not provide a way to fix specific errors. this article will summarize the 5 most common windows errors and how to fix them.