None
EN
How I stole the identity of every Yahoo user
[]
Blog | Sam Curry
By inserting these "carriage return, line feed" symbols within their request, the attacker can add additional HTTP headers that will override headers stated after the injection point. If a user receives an email they’ll usually have to click “allow images”, but if the email is from an explicitly defined admin@yahoo.com then the images are automatically loaded. By sending emails as anyone from Yahoo, attackers can send HTTP 401 attacks (image authentication injection) to victims browsing with an insecure browser.