Re: CSS implication

From: HarryM (harrym@the-group.org)
Date: 03/21/02


From: "HarryM" <harrym@the-group.org>
To: "b0iler _" <b0iler@hotmail.com>, <vuln-dev@securityfocus.com>
Date: Thu, 21 Mar 2002 10:18:11 -0000


> Although very simular to XSS writting SSI, PHP, or any other kind of
server
> side language is not XSS, but rather a remote file writting vulnerability.
> The difference is there and I don't feel we should confuse the two. I am
> not sure if you would call client side scriptting that is saved to a file
on
> the server XSS, but I personally do not count it as such.

I don't agree at all, if anything, grabbing a file from another site and
executing php in it is more XSS as I understand it, since you're 'crossing'
servers to get the code. If this isn't XSS then what about reaching to
another domain to download a .js file for execution, like the recent
vulnerabilities on online news pages? Perhaps there should be different
terms for clientside/serverside XSS vulns but i feel they fall under the
same category.

Harry



Relevant Pages

  • Re: [Full-disclosure] on xss and its technical merit
    ... In this case 10000 XSS sounds a lot more valuable. ... server running the ftpd daemon) or the data/personal machines of the users ... Keep in mind that many client side exploits are XSS for the browser, ...
    (Full-Disclosure)
  • [NT] LiteServe Directory Index Cross-Site Scripting
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Web, email and FTP server. ... This is similar to the Apache XSS of last month. ...
    (Securiteam)
  • [Full-Disclosure] Eudora Worldmail Server 2.0 -XSS Injection
    ... Server: ISOCOR web500gw 2.0.0.3 ... enter sum cool XSS... ... I belive LDAP has some DCOM connectivity, and there could be issues with the LDAP... ... Vendor Fix: ...
    (Full-Disclosure)
  • Re: [Full-disclosure] on xss and its technical merit
    ... In this case 10000 XSS sounds a lot more valuable. ... server running the ftpd daemon) or the data/personal machines of the users ... Google Search Interface is as valuable as remotely exploitable buffer ...
    (Full-Disclosure)
  • Re: CSS implication
    ... Although very simular to XSS writting SSI, PHP, or any other kind of server ... but rather a remote file writting vulnerability. ...
    (Vuln-Dev)