Google accounts SSL login page suffers from highly critical XSS

Written by Dimitris Pagkalos

Wednesday, 12 November 2008

In this case, the fact that SSL is being used on the login page, does not necessarily mean that the users' login information is secured.


read more...

Google cross domain frame injection vulnerability

Written by Dimitris Pagkalos

Saturday, 11 October 2008

Dan Goodin wrote a good article on TheRegister.co.uk about the titled issue. This is not really a new vulnerability.


read more...

New Orkut XSS worm by Brazilian web security group

Written by Dimitris Pagkalos

Saturday, 4 October 2008

Security researchers Octane[F/X], Rodrigo Lacerda and Klay Gomes were able to hack again Orkut  with their new XSS worm.


read more...

Citibank's critical cross-site scripting vulnerabilities

Written by Dimitris Pagkalos

Saturday, 16 August 2008

DaiMon and mox have discovered two critical XSS flaws on Citibank's website.


read more...

Justin.tv non-malicious cross-site scripting worm

Written by Dimitris Pagkalos

Tuesday, 8 July 2008

x2Fusion from TheDefaced.org security team, recently contacted us in regards to a serious XSS vulnerability on the popular lifecasting website Justin.tv.


read more...

ICANN and IANA domains hijacked by Turkish crackers

Written by Marcelo "Vympel" Almeida and Kevin Fernandez

Thursday, 26 June 2008

The ICANN and IANA websites were defaced earlier today by a Turkish group called "NetDevilz". ICANN is responsible for the global coordination of the Internet's system of unique identifiers. These include domain names, as well as the addresses used in a variety of Internet protocols.


read more...

2 3 4 5 6 7 8 9 10 

 

31265 total xss
1554 fixed
5238 xss onhold
920 EW subscribers


Home | News | Articles | Advisories | Submit | Alerts | Links | What is XSS | About | Contact | Some Rights Reserved.