Re: Cross Site Scripting Vulnerabilities - XSS
From: Bill Pennington (billp@boarder.org)Date: 08/07/02
- Previous message: Maximiliano Caceres: "Syscall Proxying: whitepaper and samples release"
- Maybe in reply to: Jason binger: "Cross Site Scripting Vulnerabilities - XSS"
- Next in thread: Kevin Spett: "Re: Cross Site Scripting Vulnerabilities - XSS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 06 Aug 2002 16:37:23 -0700 From: Bill Pennington <billp@boarder.org> To: Matt Andreko <mandreko@ori.net>, pen-test <pen-test@securityfocus.com>
In order for that to be useful you need to get someone else to click on the
link. This is generally not to difficult depending on your target. Remember
e-mail is easily forged.
On 8/6/02 2:56 PM, "Matt Andreko" <mandreko@ori.net> wrote:
> I am kinda new to XSS, but am intrigued by how it works. I have found
> sometimes you can get javascript messages to pop up and such, but if
> it's not being stored in a database, what good is it?
>
> Take for example Iwillusa.com (a motherboard maker's website). They
> have a product page that I saw had some html in the URL:
> http://www.iwillusa.com/products/spec.asp?ModelName=DVD266>u</i>-RN&Su
> pportID=
> I edited it and it became:
> http://www.iwillusa.com/products/spec.asp?ModelName=DVD266u-RN