|
|||||||||||
|
RE: XSS
From: Brett Moore <brett(at)softwarecreations.co.nz>
Date: Tue Dec 10 2002 - 16:59:50 EST
In this particular instance this scenario may work. The vuln site is widgets.com and has a xxs flaw. I run a news story on my site saying widgets.com is going out of business because of '.......' and give a link to widgets.com/<xss stuff>, people clicking on the link will be taken to widgets.com and shown an iframe with the fake new story. This will appear as if it is actually on widgets.com and thus believable. Another use of xss which I have not seen mentioned is. If the page that has xss holes, also displays information such as passwords, then the XSS can be used to grep the info from the page and send it back out to the net. Brett > -----Original Message-----
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:46 EDT |
||||||||||
|
|||||||||||