XSS flaws found on three security firms' websites


  1. Posts : 53,363
    Windows 10 Home x64
       #1

    XSS flaws found on three security firms' websites


    A group of white-hat hackers has discovered various XSS vulnerabilities on websites belonging to three well-known security companies, and have reported it to the firms themselves so that they can fix them them as soon as possible.

    "XSS vulnerability is a high level vulnerability which could allow an attacker to steal sensitive data such as login information and other credentials," said one of the members of white-hat Team Elite to The Register. "I've noticed that all three security vendors have fixed the bugs on their websites, which is very positive."

    The three security firms in question are Symantec, Eset and Panda Security, and as the group points out, these XSS flaws could easily allow attackers to push their own malicious content to visitors or for executing phishing attacks. XSS flaws basically happen because of errors in coding, but one would think that security firms would be especially careful to avoid things like that on their pages.

    Fortunately, it seems these particular flaws have not been misused before the patching, but this instance should be a lesson for us all. And that lesson is - always keep your eyes on the ball.
    Source

    A Guy
      My Computer


  2. Posts : 759
    W7-Enterprise + WS-2008 (Converted to Workstation)
       #2

    hi !

    THANKS A Guy !

    interesting.
      My Computer


  3. Posts : 622
    Arch Linux 64-bit
       #3

    This must be a second set of XSS bugs found on ESET and Symantec websites.

    Bugs on Kaspersky, BitDefender, Avast, McAfee, AVG, F-Secure, and Avira websites have also been found.

    And that's only of the anti-virus vendor websites, I know of. There have also been bugs on other big name websites found, such as on Ebay, Intel and certain American banking websites, to name a few.

    Most of them found by members of Team Elite, I believe.
      My Computer


 

Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:19.
Find Us