Microsoft leaves an open door to phishers!

Written by Giovanni Delvecchio, Zone-H.org

Wednesday, 11 April 2007

Cyber criminals often appeal to users' unawareness and good faith to design their attacks, and in spite of constant information made by journals, blogs, magazines and IT Security organizations, this phenomenon, and specially the number of victims, keeps growing. But what happens when a site considered as trusted, actually contains a “trap” for the user?


read more...

Cross-site framed?

Written by Dimitris Pagkalos and Kevin Fernandez

Tuesday, 27 March 2007

Have you heard of cross-site framing? The past few days I saw listed on our archive, several websites vulnerable to cross-site framing - listed as frame redirection. I will briefly describe a possible exploitation scenario, concluding with more emphasis on the negative impact that this type of vulnerability can have to the privacy of innocent individuals who are users of the affected websites.


read more...

Digg.com is vulnerable to another XSS

Written by DP

Monday, 26 March 2007

Brendandonhue from xssblog.com, notified us about a cross-site scripting vulnerability which he discovered on Digg.com - the popular user driven social content website. Malicious people can exploit this vulnerability to compromise user accounts and perform cross-site request forgeries (CSRF) -  for example, when an attacker forces the victim to Digg his story.


read more...

Jikto: the JavaScript-based threat

Written by Roberto Preatoni, Zone-H.org

Thursday, 22 March 2007

Do you know Jikto? It is a new tool written in JavaScript that could be used by cyber crooks on PCs of unknowing users to make them do illegal activities without directly commandeer the systems. According to Jikto creator Bill Hoffman, researcher at web security firm SPI Dynamics, this is going to drastically change the scope of evil things you can do with JavaScript.


read more...

IE7 users: beware of "Navigation Canceled" errors!

Written by Kevin Fernandez

Thursday, 15 March 2007

Did you feel secure with your brand new Internet Explorer 7? Well, Aviv Raff published on his blog an interesting vulnerability affecting it: a cross-site scripting in the navcancl.htm local resource.


read more...

XSSed.com: What, Who, Why?

Written by Dimitris Pagkalos and Kevin Fernandez

Tuesday, 6 March 2007

The goals of XSSed.com are to provide informative resources on cross-site scripting (XSS) vulnerabilities and exploitation methodologies, and to archive XSS vulnerable websites for statistic purposes. Mirroring websites is a way to prove to vendors and webmasters, that the vulnerability really existed - in case of denial. Users will become more aware on protecting themselves on some websites, as XSS vulnerabilities are mostly targeting the users and not the websites.


read more...

1 2 3 4 5 6 7 8 9 10 11 12 13 

 

35984 total xss
11629 special xss
1889 fixed
7829 xss onhold
1516 EW subscribers

Home | News | Articles | Advisories | Submit | Alerts | Links | What is XSS | About | Contact | Some Rights Reserved.