Hi,
I realized a PoC of what I define a XWW - Cross webmail worm, based on
exploitation of XSS vulnerabilities.
For the PoC I've tested the worm code on 4 popular Italian webmails:
o Libero.it
o Tiscali.it
o Lycos.it
o Excite.com
Detailed informations and a video can be found at:
http://rosario.valotta.googlepages.com/home
Regards,
Rosario Valotta
rosario dot valotta at gmail.com
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Received on Jul 09 2007