Re: [Full-disclosure] The Next Super JavaScript Malware - the web has crashed



Dear petko d. petkov,
I don't know if it was your intention, but you're giving a bad name to
xssed.com, which goal is to organize the public XSS vulnerabilities, make
statistics, and first of all to spread education about XSS
vulnerabilities. While the scenario you describe is somehow possible, it
relies on the availability of our web site, and we'd be able to stop it
quickly. Anybody would be able to build such list of XSS list without the
need of our site, and with their own discoveries. I wanted to clarify it.
Anyway i think that everybody here on the list knows the dangers and
advantages of full disclosure..

Kevin

http://www.gnucitizen.org/blog/the-next-super-worm

In this article I explain a technique that can be used by malicious
minds to build the next generation of JavaScript based malware. The
post is for education purposes and I welcome everyone who has ideas
how to stop these types of attacks to do so by sending an email or
posting a comment. We do really need to start thinking about how to
fight back and start developing strategies that can apply.

cheers

--
pdp (architect) | petko d. petkov
http://www.gnucitizen.org

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: [Full-disclosure] Gmail 0day
    ... Your Gmail session is hijacked (i.e.: via the XSS PoC posted on FD) ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • =?KOI8-R?Q?Re:_[Full-disclosure]_XSS_at_msn.com_=C9_cisco.com?=
    ... It looks like I have:) See my next message "XSS at nsa.gov" or just visit ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Gmail 0day
    ... Blackhat SEO XSS ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ... Full-Disclosure - We believe in xss. ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Month of ActiveX Bug
    ... [Full-disclosure] Month of ActiveX Bug ... Even XSS bugs in open source perl webmail apps. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • RE: [Full-disclosure] Not even the NSA can get it right
    ... What would XSS on NSA.GOV get a hacker anyways? ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)