lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Sat, 30 Jan 2010 11:02:21 -0300
From: "Zerial." <fernando@...ial.org>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: The future of XSS attacks

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi MustLive:

I've translated to Spanish your article:
http://blog.zerial.org/seguridad/el-futuro-de-los-ataques-cross-site-scripting-xss/

cheers.


On 01/22/10 16:08, MustLive wrote:
> Hello participants of Full-Disclosure!
> 
> Yesterday I wrote English version of my article The future of XSS attacks
> (http://websecurity.com.ua/3878/), which you can read if you interested in
> this topic.
> 
> In the article I talked about Cross-Site Scripting attacks where it’s not
> possible to use any tags and angle brackets. I listed attack vectors which
> can be used in this case (automated and non-automated). And wrote about
> current situation with modern browsers: in 2008 in Firefox 3 possibility of
> attack via -moz-binding was removed (partly) and in IE 8, which released at
> beginning of 2009, support of expression() was removed.
> 
> So I proposed my cross-browser solution for conducting of automated XSS
> attacks in such conditions (when it’s not possible to use any tags and angle
> brackets) - with using of MouseOverJacking technique, which I already wrote
> about (http://websecurity.com.ua/3814/).
> 
> You can read the article The future of XSS attacks at my site:
> http://websecurity.com.ua/3878/
> 
> Best wishes & regards,
> MustLive
> Administrator of Websecurity web site
> http://websecurity.com.ua
> 
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/


- -- 
Fernando A. Lagos Berardi - Zerial
Desarrollador y Programador Web
Seguridad Informatica
GNU/Linux User #382319
Blog: http://blog.zerial.org
Skype: erzerial
Jabber: zerial@...beres.org
GTalk: fernando@...ial.org

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAktkO+0ACgkQIP17Kywx9JREcACgm2i9xZl/f258Hxe5SQeFOuBS
pxMAoI34j+3SYPpLWi/j9bvGRyoQ0mPl
=Ks9y
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists