Full Disclosure mailing list archives

Re: Re: Google is vulnerable from XSS attack


From: c0ntex <c0ntexb () gmail com>
Date: Wed, 7 Dec 2005 22:16:52 +0000

For what it is worth, it would be trivial right now to name 10 very
large online presences that have some form of vulnerability, whether
that is XXS, SQL Injection or some other form of web application
quirkiness, it's not really a big deal.

I do how ever have to agree with ad, it takes far more skill, patience
and devotion to develop some form of code based exploit, by either
controlling a chunk of memory or a vital register which in the end
yields some form of malicious process control than it does to pop an
html, java script or sql string/statement in to a field or other input
area.

On 07/12/05, ad () heapoverflow com <ad () heapoverflow com> wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

where is your heap overflow ?? (XSS easy targets) ;>

n3td3v wrote:
Hackers own Google while vulnerabilities remain unpatched. Once they
patch a vulnerability, they can own me again! Until then... Google is
in the hands of hackers.

Since you're having a stab at me. Wheres your Google and Yahoo
vulnerabilities? Naw, you don't have any. You prefer to go looking for
your SQL injections and cross site scripting in web sites no one has
ever heard of or cared about before (easy targets).

As the score goes, how many high profile brand names have you found
vulnerabilities for?

Fancy having a hacking challenge for finding vulnerabilities in major dot-com's?

Lets do it!

On 12/7/05, Morning Wood <se_cur_ity () hotmail com> wrote:

who owns you? hint: Google ( they own the world )

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/




-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (MingW32)

iQIVAwUBQ5dYr6+LRXunxpxfAQImGRAAj0gfdT3D3Y5XS5H4iIDujA3l8fCXah0F
vOxvmPWSFgIvicoNTITrX/MNCqnFXhR5tpbk3m4gUsfb+i4VHoEiNy/GcT3XB2VY
ZDSqA3lso3kNH9g+LrVMkI9TnLLKJxicbiJRNFusCQcKECDivipuU/hdMiWM/M2j
h+Uh9bCrl5cWFRcsj8WZDeOZu2jtR4lsh96zdkZAQ+IT9M+auwRAoi9KUvcVuyCO
8zoFPmLUsecMU0fc7IeTtODZrhgR9IDQ0kqfRGJpuyR97du7TZrFs+yqzgMn9C2E
AU+5b3B51Mi62yGpAvXf89nboMoNOoHNdsd2XhuY36VtRoNeuv0PGDIpB5uxlq+v
OezZ9JcBeWYzxXvwlLB4rSlcsN77uR9DoPvx/bCHQLXd2O/1w01/D5PZw3VUHvxJ
p7v1FRPBGshqG53RkATbZFKwCyZebYTWbY4E/8hOne1m+wH9hZEk6TVfKwtOmFwE
/z5vO2jgULeTTKMOrDWQyaiRRC2Kz5iN7BLTBLOVU2nWTPkY2l06dQoo9xXQ/fnS
MmIyzIYbA+Yc17rddxuRM3TCJ7OBbETQkuOBIFNlTRg2UwnzXskAhxD2H9Qyc9hu
CPWTQ6IEbB6jMTP18WChzYr5yk475bYLxghdIktvMteCgAB1Q0FxL/bhuVRf8Ipv
v4guvZNJVhs=
=wspa
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



--

regards
c0ntex
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: