Cross Site Scripting (XSS)

WHID 2008-04: RIAA web site cleared

WHID 2005-11: Samy XSS Worm Hits MySpace

The Samy worm at my space is now a classic, both a sophisticated attack and a well documented one, it became a case study in the web application security field. Recently Robert Hansen (RSnake) wrote a very interesting blog entry about Samy and what happened to him since.

Additional information:

WHID 2008-20: XSS Worm At Justin.tv Affects 2525 Profiles

A proof of concept XSS worm crawled justin.tv, a popular lifecasting platform. The warm succeeded in planting a self replicating code on 2525 accounts in less than 24 hours before the vulnerability was fixed.

Additional information:

Syndicate content