Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: XSS

From: Brett Moore <brett(at)softwarecreations.co.nz>
Date: Tue Dec 10 2002 - 16:59:50 EST


Hey zeno, and others...

In this particular instance this scenario may work.

The vuln site is widgets.com and has a xxs flaw.

I run a news story on my site saying widgets.com is going out of business because of '.......' and give a link to widgets.com/<xss stuff>, people clicking on the link will be taken to widgets.com and shown an iframe with the fake new story. This will appear as if it is actually on widgets.com and thus believable.

Another use of xss which I have not seen mentioned is.

If the page that has xss holes, also displays information such as passwords, then the XSS can be used to grep the info from the page and send it back out to the net.

Brett

> -----Original Message-----
Received on Tue Dec 10 17:54:00 2002

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:46 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library