Shellshock: Romanian hackers are accessing Yahoo servers, claims security expert

Hackers are exploiting Yahoo’s bash bug vulnerability, according to technology consultant Jonathan Hall

Yahoo servers have been infiltrated by Romanian hackers exploiting the Shellshock bug discovered last month, according to cyber security expert Jonathan Hall.

In a blog post on his website Future South, Hall detailed the process by which he discovered Yahoo, Lycos and WinZip websites had all been infiltrated by a group of Romanian hackers.

Hall had Google-searched a range of codes designed to identify which servers were vulnerable to Shellshock, and found that Romanian hackers had breached two Yahoo servers and were exploring the network in search of access points for Yahoo!Games, which has millions of users.

Yahoo’s servers were vulnerable to attack because they were using an old version of server technology Bash.

A Yahoo told The Independent: “A security flaw, called Shellshock, that could expose vulnerabilities in many web servers was identified on September 24.

As soon as we became aware of the issue, we began patching our systems and have been closely monitoring our network.

Last night, we isolated a handful of our impacted servers and at this time we have no evidence of a compromise to user data. 

We’re focused on providing the most secure experience possible for our users worldwide and are continuously working to protect our users’ data.”

mayer2.jpg
Yahoo CEO Marissa Mayer was alerted to the Shellshock hacks

Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Marissa Mayer.

It was confirmed to him that its servers had been infiltrated but Yahoo refused to pay him for alerting them as it was not part of the company’s bug bounty programme.

Yahoo is notorious for its disregard of bug bounty hunters, having last year rewarded one such hacker who identified three bugs in Yahoo's servers with a $25 voucher for company merchandise.

Also in his ethical-hack investigation, Hall found that hackers were using the WinZip domain - for the zip file creator/extractor - to locate other possibly accessible servers.

“This breach affects ALL of us in one way or another, and it’s crucial that this problem be resolved with haste,” Hall said.

Hall informed the FBI of the hackings.

Romania is known as a hub for cyber crime; more than $1 billion stolen in the US by Romanian hackers in 2012, according to the American ambassador in Bucharest.

More Bash bug: Governments rush to protect critical infrastructure
What is Shellshock?

This is the first high profile Shellshock hack since its discovery last month. The bash vulnerability, which has been around for 20 years, is widely considered the “worst ever computer bug.”

It affects computers running Unix and Linux, including Apple's OS X, and gives hackers complete access to everything that is stored on the compromised server.

Comments