15 August 2006

XSS, Cookies, and Session ID Authentication - Three Ingredients for a Successful Hack

Posted by Mikhail Esteves under: General .

Cross site scripting (XSS) attacks are often seen as a powerless hack. While this is true in some cases, for the most part the impact of an XSS vulnerability is left up to the imagination and talent of the attacker. In this article I am going to look at a real-life XSS attack and how it was used to bypass the authentication scheme of an online web application I was asked to test. In this case, the XSS resulted led to “shell” access to the web server — anything but harmless.

Link



Leave a Reply

Browse

Photography

Projects

Pages

Calendar

August 2006
M T W T F S S
« Jul   Sep »
 123456
78910111213
14151617181920
21222324252627
28293031  

Categories

www.flickr.com

Use OpenDNS