Yahoo servers have been infiltrated by Romanian hackers exploiting the Shellshock bug discovered last month, according to cyber security expert Jonathan Hall.
Hall had Google-searched a range of codes designed to identify which servers were vulnerable to Shellshock, and found that Romanian hackers had breached two Yahoo servers and were exploring the network in search of access points for Yahoo!Games, which has millions of users.
Yahooâ€™s servers were vulnerable to attack because they were using an old version of server technology Bash.
A Yahoo told The Independent: â€œA security flaw, called Shellshock, that could expose vulnerabilities in many web servers was identified on September 24.
As soon as we became aware of the issue, we began patching our systems and have been closely monitoring our network.
Last night, we isolated a handful of our impacted servers and at this time we have no evidence of a compromise to user data.
Weâ€™re focused on providing the most secure experience possible for our users worldwide and are continuously working to protect our usersâ€™ data.â€
Yahoo CEO Marissa Mayer was alerted to the Shellshock hacks Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Marissa Mayer.
It was confirmed to him that its servers had been infiltrated but Yahoo refused to pay him for alerting them as it was not part of the companyâ€™s bug bounty programme.
Yahoo is notorious for its disregard of bug bounty hunters, having last year rewarded one such hacker who identified three bugs in Yahoo’s servers with a $25 voucher for company merchandise.
Also in his ethical-hack investigation, Hall found that hackers were using the WinZip domain – for the zip file creator/extractor – to locate other possibly accessible servers.
â€œThis breach affects ALL of us in one way or another, and itâ€™s crucial that this problem be resolved with haste,â€ Hall said.
Hall informed the FBI of the hackings.
Romania is known as a hub for cyber crime; more than $1 billion stolen in the US by Romanian hackers in 2012, according to the American ambassador in Bucharest.
- Click to share on Facebook (Opens in new window)
- Click to share on Twitter (Opens in new window)
- Click to share on Google+ (Opens in new window)
- Click to share on WhatsApp (Opens in new window)
- Click to share on Tumblr (Opens in new window)
- Click to share on Skype (Opens in new window)
- Click to print (Opens in new window)