Title: Yahoo! Mail Filter Bypass Author: Simo Ben youssef aka _6mO_HaCk Discovered: january 2006 published: 26 july 2006 MorX Security Research Team http://www.morx.org http://www.morx.org/yahoo-firefox-bypass.txt Service: Webmail Vendor: Yahoo mail, and possibly others Vulnerability: Filter bypass / Cross Site Scripting Severity: Medium/High Tested to be vulnerable on: FireFox 1.5.0.4 not vulnerable: Microsoft IE 6.0, Opera 8.54 Details: few months ago i have published a vulnerability affecting Yahoo mail with MS IE, where yahoo mail filter failed to detect script attributes in combination with the style attribute as a tag, the combination code was: few days later yahoo patched the above combination so now if you try to send your self that code, you will see that yahoo filters it this way this is not a good way of filtering, since yahoo filtered only the "onload" attribute few days later i received some emails asking how a similar bypass-combination can be executed on other browsers such as firefox since that one worked only on IE, after making some tests i realised that firefox will execute any js code proceeded by firefox wont execute the js code in fact the first combination will not be filtered by yahoo mail, usualy yahoo filters but if proceeded by the