AOH :: HP Unsorted T :: BU-1608.HTM

The future of XSS attacks



The future of XSS attacks
The future of XSS attacks



Hello participants of Bugtraq!

Yesterday I wrote English version of my article The future of XSS attacks
(http://websecurity.com.ua/3878/), which you can read if you interested in 
this topic.

In the article I talked about Cross-Site Scripting attacks where it=92s not
possible to use any tags and angle brackets. I listed attack vectors which
can be used in this case (automated and non-automated). And wrote about
current situation with modern browsers: in 2008 in Firefox 3 possibility of
attack via -moz-binding was removed (partly) and in IE 8, which released at
beginning of 2009, support of expression() was removed.

So I proposed my cross-browser solution for conducting of automated XSS
attacks in such conditions (when it=92s not possible to use any tags and angle
brackets) - with using of MouseOverJacking technique, which I already wrote
about (http://websecurity.com.ua/3814/). 

You can read the article The future of XSS attacks at my site:
http://websecurity.com.ua/3878/ 

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua 


The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.