Yahoo Answers is shutting down on May 4th, 2021 (Eastern Time) and beginning April 20th, 2021 (Eastern Time) the Yahoo Answers website will be in read-only mode. There will be no changes to other Yahoo properties or services, or your Yahoo account. You can find more information about the Yahoo Answers shutdown and how to download your data on this help page.

Jon W
Lv 5
Jon W asked in Yahoo ProductsYahoo Answers · 1 decade ago

R U aware how serious the "man" problem could be? It's not about points. This is a serious, planned attack.

Just a couple observations. Have to use some jargon & don't have room to define all terms. (Y!A is Yahoo! Answers).

Most people seem to be fixated on the points - or inconvenience.

Those are just side-effects and/or means to an end.

Y!A - I'm sure has a top notch security staff, but have not been able to stop this yet. That indicates it's using hijacked PC's to run the bots (perhaps yours) so Y!A cannot easily block them.

The bots had to be installed sometime in advance (Step 1).

The adaptive changing of names & web site addresses (today switched to hexadecimal to obfuscate them) is clever. This has all of the earmarks of a very well planned attack.

It is about the virus or the virus payload. Deleting the virus may not get the payload.

Routers & Windows firewall does nothing to prevent this type of infection. It has likely infected many thousands of machines (Step 2).

I even clicked on it accidentally! (was using FireFox & noscript, so I was not infected)

Step 3 will be coming.

Update:

I agree that it should have been caught much sooner! There are more than a few problems with answers. Hopefully, they will add that in response to this.

Regardless of the time - someone should be at least skimming watching the the abuse reports scroll by .

Failing that, at the very least, networking should have noticed the increase in traffic compared to the norms. Not just the people - the traffic monitoring software (such as Openview) should have highlighted it.

Update 2:

I don't know what step 3 is - that's the concern.

There may not be a step 3.

Some exploits this past year have gone through the steps but not done any damage. These are generally regarded as test runs.

If there's one thing about hackers - quality is job 1. It would be a shame to go to all of the trouble of setting this up, and then have it fail on some stupid programming error.

Then, you have also alerted your target(s) and blown your chance.

I thought I could fit this in one added detail. It will have to be two probably...

-------------

Why Y!A?

1. Because they can.

They have found an hole in Yahoo answers.

It's not always easy to find such a gaping hole.

2. The extent of the exploit is not yet truly known.

Once you've broken down the front door - who knows what's up for grabs?

Example:

Y!A protects your email and IM addresses from being seen.

Y!A also keeps you from getting 5000 points in one day.

Y!A knows your yahoo id also.

What will happen to the ones with the virus?

4 Answers

Relevance
  • Anonymous
    1 decade ago
    Favorite Answer

    It bothers me because it makes me wonder what the purpose for what they did is. I think that you are right about this being serious. The bots seem to be coming from computers in China.

    Yahoo staff posted to the Y!A Forum saying that the following accounts have been suspended..

    MAN

    people

    orcal_girl

    answer_moon

    If you encounter any more, let Yahoo know.

    Source(s): Y!A Forum
  • Zloar
    Lv 4
    1 decade ago

    I have been fixated on the points, but not because I'm jealous of their ability to get to high levels... I have been fixated on the points, because I am astonished that the Yahoo! Answers team cannot detect a spammer getting hundreds of points in the matter of minutes. Any legitimate user couldn't possibly answer more than 3-5 answers a minute. A spam bot should be easily detected and dealt with within the first 10 mins of operation!

  • Anonymous
    1 decade ago

    1) What is the point of the attack, then?

    2) What IS step 3?

  • SLH
    Lv 6
    1 decade ago

    my question is why would they want to attack Y!A?

Still have questions? Get your answers by asking now.