|
|||||||||||
|
RE: XSS
From: Eyal Udassin <eyal(at)webcohort.com>
Date: Tue Dec 10 2002 - 10:23:11 EST There are two main issues concerning XSS:
1.
XSS in that manner is a very good way to run scripts on cautious clients that allow only very specific sites to send them scripts.
2.
-----Original Message-----
Being new to XSS and seing alot of messages in the last couple weeks on the subject got me wondering... What is the real vulnerability if the site in questions is vulnerable to XSS but does not let you write any malicious scripts on the system, like message board, forums etc... ? Can anything be done to exploit XSS if the above scenario occurs ? I know it depends on the web server, packages installed etc... I'm asking in generaly is it possible ? You can do the document.cookie and view your cookie, that migth give a hint on the structure but... or redirect yourself to another web site :) etc... I've read the document on XSS by David Endler http://www.idefense.com/papers.html but still have some questions. If possible, can the XSS guru's on the list shed some light on the subject. Thanks for your time, Cheers Do you Yahoo!? Yahoo! Mail Plus - Powerful. Affordable. Sign up now. http://mailplus.yahoo.com Received on Tue Dec 10 10:33:53 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:46 EDT |
||||||||||
|
|||||||||||