[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <80edc5220811081719x43e41729t4497d7b0fcd612dd@mail.gmail.com>
Date: Sun, 9 Nov 2008 12:19:11 +1100
From: kuza55 <kuza55@...il.com>
To: rholgstad <rholgstad@...il.com>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: Metrica Service Assurance Multiple Cross Site
Scripting
2008/11/9 rholgstad <rholgstad@...il.com>:
> post auth xss
>
> *yawn*
I don't quite see your point about it being post auth.
The URLs provided don't seem to have csrf tokens or anything else that
actually requires an attacker to have an account, so all you need to
do is find an authed victim, which is what you would have to do anyway
since attacking unauthed victims is usually pretty pointless (not that
you can't still perform useful attacks, but they're not always
possible or simple).
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists