Yahoo! CAPTCHA Has been broken

According to these Russians, They cracked the Yahoo Captcha and are giving away how they did it here.

Create Instant Buzz

Cross Site Scripting on Whois

Here’s a very nice XSS find by Klaus:
“Most domain registrars (have yet to find one that does) will not filter what you put on your REGISTRANT CONTACT INFO and WILL allow the script tag! ”
Considering how many sites scrape or use Whois info, I’d say that a hole like that is pretty massive for hackers.
[…]