The future of XSS attacks



Hello participants of Bugtraq!

Yesterday I wrote English version of my article The future of XSS attacks
(http://websecurity.com.ua/3878/), which you can read if you interested in
this topic.

In the article I talked about Cross-Site Scripting attacks where it’s not
possible to use any tags and angle brackets. I listed attack vectors which
can be used in this case (automated and non-automated). And wrote about
current situation with modern browsers: in 2008 in Firefox 3 possibility of
attack via -moz-binding was removed (partly) and in IE 8, which released at
beginning of 2009, support of expression() was removed.

So I proposed my cross-browser solution for conducting of automated XSS
attacks in such conditions (when it’s not possible to use any tags and angle
brackets) - with using of MouseOverJacking technique, which I already wrote
about (http://websecurity.com.ua/3814/).

You can read the article The future of XSS attacks at my site:
http://websecurity.com.ua/3878/

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua



Relevant Pages

  • Re: Cross Site scripting prevention at browser
    ... >> Given the present state of XSS attacks, ... >> How is JavaScript handled at the browser level?. ... >> In order to prevent such attacks, is it possible for my browser to ... >scripting engine in what should be a secure sandbox. ...
    (comp.security.unix)
  • Re: Internet Explorer 8 beta and xss filter...
    ... The link you submited describes the protection offered by IE8 as ... expect that the number of unintended attacks decrease. ... JLV> hey guys... ... JLV> do you think this will put a stop on xss attacks by Microsoft and their ...
    (Security-Basics)
  • Re: [Full-disclosure] The future of XSS attacks
    ... Yesterday I wrote English version of my article The future of XSS attacks ... GNU/Linux User #382319 ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ ...
    (Full-Disclosure)
  • [Full-disclosure] The future of XSS attacks
    ... Yesterday I wrote English version of my article The future of XSS attacks ... So I proposed my cross-browser solution for conducting of automated XSS ... Administrator of Websecurity web site ...
    (Full-Disclosure)
  • [Full-disclosure] Dark side of bookmarks
    ... After my articles about different attacks via redirectors - Redirectors: ... time about attacks via bookmarks. ... Administrator of Websecurity web site ...
    (Full-Disclosure)