Well, well, well, it is that time of the day again, when a demo on NASA fails ... ;)
They fixed the bug in 3 days, which is not bad ...
Cheers,
Kish
Tuesday, January 27, 2009
NASA fixed the XSS
Labels:
Crimemachine,
Hack,
Hacking,
Insecure,
Insecure Times,
nasa,
nasa.gov,
Web Hacking,
Whack,
XSS
Saturday, January 24, 2009
XSS in NASA website, again
#########################################
# Website: http://www.nasa.gov
# It's time to know more about astronauts and gravity
# Bug: XSS
# Date: 24.01.09
########################################
Vulnerable URL: hxxp://astrogravs.nasa.gov
Click here for the demo
Fix input validation in the page.
Cheers :)
Kish
# Website: http://www.nasa.gov
# It's time to know more about astronauts and gravity
# Bug: XSS
# Date: 24.01.09
########################################
Vulnerable URL: hxxp://astrogravs.nasa.gov
Click here for the demo
Fix input validation in the page.
Cheers :)
Kish
Labels:
Crimemachine,
Hack,
Hacking,
Insecure,
Insecure Times,
nasa,
nasa.gov,
Web Hacking,
Whack,
XSS
Thursday, January 22, 2009
XSS in Facebook
###################################
# Website: http://www.facebook.com
# It's free and anyone can hack !
# Bug: XSS
# Date: 22.01.09
##################################
Vulnerable URL: hxxp://apps.facebook.com/skillzbase/
Click here for the XSS Demo
Fix input validation in the app
Social networking websites are targetted a lot these days, reckless filtering *shrugs*
Cheers :)
Kish
Date: 24.01.09
Update: The bug has been fixed by Facebook, Full disclosure - We believe in it !
# Website: http://www.facebook.com
# It's free and anyone can hack !
# Bug: XSS
# Date: 22.01.09
##################################
Vulnerable URL: hxxp://apps.facebook.com/skillzbase/
Click here for the XSS Demo
Fix input validation in the app
Social networking websites are targetted a lot these days, reckless filtering *shrugs*
Cheers :)
Kish
Date: 24.01.09
Update: The bug has been fixed by Facebook, Full disclosure - We believe in it !
Labels:
Apps,
Crimemachine,
Facebook,
Facebook Apps,
Hack,
Hacking,
Insecure,
Insecure Times,
social networking,
Web Hacking,
Whack,
XSS
Thursday, January 15, 2009
XSS in DMOZ Search
Advisory #1 (2009)
############################
# Website: dmoz.org
# Bug: HTML Injection, XSS
# Date: 15.01.09
###########################
Vulnerable URL: http://search.dmoz.org/cgi-bin/search?search=
Click here for a demo
Next screenshot to show the presence of XSS bug
Click here for demo
Fix input validation in these pages for better security.
Cheers,
Kish
############################
# Website: dmoz.org
# Bug: HTML Injection, XSS
# Date: 15.01.09
###########################
Vulnerable URL: http://search.dmoz.org/cgi-bin/search?search=
Click here for a demo
Next screenshot to show the presence of XSS bug
Click here for demo
Fix input validation in these pages for better security.
Cheers,
Kish
Labels:
Crimemachine,
dmoz,
Hack,
Hacking,
HTML Injection,
Insecure,
Insecure Times,
Web Hacking,
Whack,
XSS
Subscribe to:
Posts (Atom)