full-disclosure-uk January 2010 archive
Main Archive Page > Month Archives  > full-disclosure-uk archives
full-disclosure-uk: [Full-disclosure] The future of XSS attacks

[Full-disclosure] The future of XSS attacks

From: MustLive <mustlive_at_nospam>
Date: Fri Jan 22 2010 - 19:08:51 GMT
To: <full-disclosure@lists.grok.org.uk>


Hello participants of Full-Disclosure!

Yesterday I wrote English version of my article The future of XSS attacks (http://websecurity.com.ua/3878/), which you can read if you interested in this topic.

In the article I talked about Cross-Site Scripting attacks where itís not possible to use any tags and angle brackets. I listed attack vectors which can be used in this case (automated and non-automated). And wrote about current situation with modern browsers: in 2008 in Firefox 3 possibility of attack via -moz-binding was removed (partly) and in IE 8, which released at beginning of 2009, support of expression() was removed.

So I proposed my cross-browser solution for conducting of automated XSS attacks in such conditions (when itís not possible to use any tags and angle brackets) - with using of MouseOverJacking technique, which I already wrote about (http://websecurity.com.ua/3814/).

You can read the article The future of XSS attacks at my site: http://websecurity.com.ua/3878/

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua



Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/