Someone should post some ?@*~ to some ?@*~' social ?@*~ to attract some ?@*~ people

Etiketler social shit, xss, xss shell, ajax, 24.06.2006

Ok, fill in the blanks...

AJAX was a great and successful shot. I mean we all know and was doing similar things like AJAX. Didn't you know "remote scripting" from Microsoft? Shame on you. Someone (no offense - in fact I totally support and respect to these and similiar actions) put it public in a well documented way, tested method and with some great samples.

I just read slashdot headers, XSS Vulnerabilities Reviewed and Re-Classified (hmm? don't expect too much it's just a reminder)

Thanks to neosmart to point it again. People starting to understand impact of XSS attacks after "Samy is my hero (was really fun)" or recent "Yahoo worm attack". I'm always saying this, "XSS is not important because of its impact, It's important because you can find it virtually anywhere!"

Sometimes even in a 3rd party client application like Flash player.

uLr!cH - 08.09.2006

Effectively exploitation of an xss vulnerability is the most significant part of the problem because it is very easy to spot them by using our favourite search engine, google. You can make search queries by using google's operators. Here's something handy: "inurl:search.asp"

Yorum Yazın


Tüm yorumlar onaydan geçmektedir, bu işlem en uzun 30 dk. sürecektir. E-mail adresleri yeni yorumları bildirme harici hiç bir başka amaçla kullanılmamaktadır ve sitede gözükmemektedir.



Captcha Kodu