Yahoo Says Some Systems Breached, But Not by Shellshock

Advertisement
By Agence France-Presse | Updated: 8 October 2014 09:07 IST
Yahoo said some of its servers were breached briefly by hackers, but that the attack was unrelated to the newly discovered Shellshock vulnerability, and that no user data was compromised.

In a posting late Monday on the Hacker News forum, Yahoo's chief information security officer Alex Stamos said hackers managed to breach three of its sports servers that deliver live game-streaming data.

"After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock," Stamos wrote, referring to the recently discovered flaw which could affect millions of computers and other Internet-connected devices.

"At this time we have found no evidence that the attackers compromised any other machines or that any user data was affected. This flaw was specific to a small number of machines and has been fixed."

Advertisement

The comments came after security researcher Jonathan Hall reported the breach, and said it was the result of the flaw known as Shellshock or Bash. On Tuesday, Hall maintained that the attack was the result of a Shellshock attack.

Advertisement

"The Yahoo infiltration WAS from the 'Shellshock' vulnerability... How do I know? Because I sat there watching it happen."

Stamos said the situation led to confusion because attackers had been trying to use the flaw to gain access.

Advertisement

"As you can imagine this episode caused some confusion in our team, since the servers in question had been successfully patched (twice!!) immediately after the Bash issue became public," he said.

"Once we ensured that the impacted servers were isolated from the network, we conducted a comprehensive trace of the attack code through our entire stack which revealed the root cause: not Shellshock."

Advertisement

The US government and technology experts warned last month of a vulnerability in some computer-operating systems, including Apple's Mac OS, which could allow widespread and serious attacks by hackers.

(Also see: 'Vast Majority of Mac Users' Not Vulnerable to Bash 'Shellshock' Exploit)

The flaw affects "Unix-based operating systems" powered by Linux and Apple's Mac OS. Apple recently said it created a patch for its operating systems, and other software firms have done the same.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  4. Motorola Edge 70 Will Launch in India Soon via This E-Commerce Platform
  5. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  6. Airtel Discontinues These Prepaid Recharge Packs in India
  7. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  8. Apple Announces App Store Awards 2025 Winners: Check List
  9. Nothing Phone 3a Lite Goes on Sale in India at This Price
  10. OTT Releases of the Week (Dec 1 – Dec 7): Know What to Watch
  1. George Clooney-Starrer Jay Kelly Now Streaming on Netflix: All You Need to Know
  2. Google's Year in Search 2025 Reveals Gemini 3, Nano Banana Pro and Other AI Search Features Launched in India 2025
  3. Polar Loop Screen-Free Fitness Tracker Launched in India With Up to Eight Days of Battery Life: Price, Specifications
  4. Xiaomi 17S Pro Said to Be in Development, Could Launch After Xiaomi 17 Ultra Debuts
  5. Motorola Edge 70 India Launch Teased; Flipkart Availability Confirmed: Expected Specifications, Features
  6. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  7. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  8. CFTC Clears Path for Spot Crypto Trading on Regulated Platforms for the First Time
  9. Realme 16 Pro+ 5G Colour Options, Memory Configurations Leaked Again; Tipped to Launch With 7,000mAh Battery
  10. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.