Sunday, May 20, 2007

Presenting the XSS Trio ;)

Site: www.googlefont.com, www.netscape.com, and www.mtv.com
Multiple XSS bugs
Risk: High



Google font - XSS



Netscape XSS



Mtv.com - nice music channel !

XSS is not an ordinary threat anymore which can just bring pop-ups, advanced and planned attacks, XSS worms like the myspace one, and nice shellcodes (like the ones showed by bill hoffman of SPI @ shmoocon are examples of ... sophistication in this area) And we can't forget XSS Proxy ... uauauauauauaua !

/Ph33r to click ...

No comments: