Yahoo Server Hack: Shellshocked Or Not?
Yahoo goes on the record to state that an attack over the weekend was not related to Shellshock, but an independent researcher insists the Bash bug is rearing its head on Yahoo infrastructure.
Contrary to news reports yesterday, an attack against several Yahoo servers this weekend was not related to Shellshock, according to Yahoo CISO Alex Stamos, who also says no user data was accessed during the attack. Stamos made his assertion after reports from the independent researcher Jonathan Hall that Romanian hackers had infiltrated Yahoo's network through the Bash bug vulnerability on its servers.
Though a company spokesperson did initially say Shellshock was to blame, Stamos said his team found that the incident was isolated to three Yahoo Sports servers, which attackers were probing for Shellshock vulnerabilities.