Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: RE: CSS, CSS & let me give you some more CSS

RE: CSS, CSS & let me give you some more CSS

From: Brian McWilliams <brian_at_pc-radio.com>
Date: Fri, 01 Feb 2002 21:29:14 -0500

At 03:09 PM 1/31/2002, Joe Harrison wrote:
>I can't help feel the importance of these cross-site-scripting attacks is
>over-emphasised.

As others have pointed out, CSS bugs can be used to do some pretty
interesting things.

FYI, the source De Vitry injected into the news site pages is here:
http://devitry.com/mon

Brian

+++

Top News Sites Close Script Hacking Hole
NEW YORK, NEW YORK, U.S.A.,
01 Feb 2002, 7:57 PM CST

http://www.newsbytes.com/news/02/174173.html

A security flaw at leading online news providers MSNBC.com, NYTimes.com,
and WashingtonPost.com could have allowed attackers to generate bogus
articles using the sites.

In a demonstration of the bug, David De Vitry, an independent security
specialist, exploited the news sites to create a phony story in which a
NASA official claimed the space agency's moon landings were faked.

The security glitch, known as cross-site scripting (CSS), opened the door
to what experts call subversion of information attacks. Such attacks can be
used to spread false information, manipulate stock prices, and perform
other malicious acts.

[snip]
Received on Feb 02 2002

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos