Full Disclosure mailing list archives
Re: Attacking the local LAN via XSS
From: Florian Weimer <fw () deneb enyo de>
Date: Thu, 10 Aug 2006 16:39:45 +0200
* pdp:
1. page that is controlled by the attacker, lets call it evil.com 2. border router vulnerable to XSS 3. user attending evil.com
This has nothing to do with cross-site scripting attacks, it's an entirely different vulnerability class called cross-site request forgery (CSRF). A lot of web applications are afffected. Technically, this is a browser vulnerability, but you can't fix it there as cross-site requests are too common in the real world. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: Attacking the local LAN via XSS, (continued)
- Re: Attacking the local LAN via XSS Georgi Guninski (Aug 04)
- Re: Attacking the local LAN via XSS pdp (architect) (Aug 04)
- Re: Attacking the local LAN via XSS Schanulleke (Aug 04)
- Re: Attacking the local LAN via XSS Siim Põder (Aug 04)
- Re: Attacking the local LAN via XSS Thierry Zoller (Aug 04)
- Re: Attacking the local LAN via XSS pdp (architect) (Aug 04)
- Re[2]: Attacking the local LAN via XSS Thierry Zoller (Aug 04)
- Re: Re[2]: Attacking the local LAN via XSS pdp (architect) (Aug 04)
- Re: Attacking the local LAN via XSS Nikolay Kubarelov (Aug 07)
- Re: Attacking the local LAN via XSS Dude VanWinkle (Aug 08)
- Re: Attacking the local LAN via XSS pdp (architect) (Aug 04)
- Re: Attacking the local LAN via XSS Georgi Guninski (Aug 04)
- Re: Attacking the local LAN via XSS pdp (architect) (Aug 04)
- Re: Attacking the local LAN via XSS Thor Larholm (Aug 04)
- Re: Attacking the local LAN via XSS pdp (architect) (Aug 04)