Yahoo Local Launches in India – Easily Hackable

Yahoo Local IndiaYahoo has launched their local search into India this week into four major cities: Delhi, Mumbai, Bangalore and Chennai. The local search in India works very much like the local search in the U.S.  To be honest, I don’t use Yahoo Local – I’ve been more of a Yelp’er or lately also searching via address using Google Maps. Though playing with Yahoo Local this morning, it’s pretty robust. I like how it aggregates reviews from across the Web in addition to those from Yahoo Local, offers an interactive map and a variety of alternative suggestions for other topics in the location I am in. I don’t see anything very innovative, the information is just presented in a very usable format.

On a more serious note, It appears that Yahoo Local India is easily hackable by injecting script code into a review and you can do basically anything from that point. Sridhar was able to create an iframe with Google in the body (see the screenshot below). He also notes that anything way more malicious could also be injected.

I tested this hack on the U.S. version of Yahoo Local and was unable to reproduce the security issue. When I entered any script code and clicked submit, the system removed the code within the script tags and prompted me to add more content.

I have submitted a ticket to Yahoo to get them to fix this.

RSS Feed
RSS
2 COMMENTS
  1. kode says:

    Allen – did you try the hack that Sridhar mentioned? Should have tried before writing this review, since
    a. the so-called-hack only works if you have firebug – it’s the plugin which is executing the code! (and not yahoo !)
    b. the code is not executed – so you cant do anything with that.

    Before you guys start taking words from stupid hackers, better try out the hack yourself (and maybe publish your own screenshot to ensure that you were able to “hack” it, the way sridhar mentioned! )

  2. Kumar.A.P.P says:

    Now,local search is exactly what India really needs. This idea is cool and is very user friendly…

Leave a Reply

Become a sponsor

SPONSORS

Loop11
Clicky Web Analytics
CloudContacts
125px
Future of Web Design
Advertise here

STARTUP NEWS

twitter