[<prev] [next>] [day] [month] [year] [list]
Message-ID: <010801c85946$de2ef020$9a8cd060$@com>
Date: Thu, 17 Jan 2008 22:23:46 +0200
From: "avivra" <avivra@...il.com>
To: "'Miroslav Lu?inskij'" <miroslav.lucinskij@...tical.lt>
Cc: <full-disclosure@...ts.grok.org.uk>, <bugtraq@...urityfocus.com>
Subject: RE: Skype videomood XSS
> I want to share some of our thoughts on Skype security.
> I will try to be short: Skype has a feature, which allows user to insert a
video into his mood - video selection is done through skype partners and is
based on regular WEB functionality.
> So this feature practically inherits WEB's problems - in this particular
case it's XSS attacks.
This is actually an exploitable Cross-Zone Scripting vulnerability.
More information here:
http://aviv.raffon.net/2008/01/17/SkypeCrosszoneScriptingVulnerability.aspx
--Aviv.
Powered by blists - more mailing lists