<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MustLive Edition" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Коментарі для запису: MOSEB-15: Vulnerabilities at images.google.com</title>
	<link>http://websecurity.com.ua/1049/</link>
	<description></description>
	<pubDate>Fri, 12 Mar 2010 00:43:55 +0000</pubDate>
	<generator>http://wordpress.org/?v=MustLive Edition</generator>

	<item>
		<title>від: MustLive</title>
		<link>http://websecurity.com.ua/1049/#comment-47365</link>
		<pubDate>Thu, 28 Jun 2007 18:55:14 +0000</pubDate>
		<guid>http://websecurity.com.ua/1049/#comment-47365</guid>
					<description>Alex, in this case Same Origin Policy (SOP) prevent access to sibling documents (and attacker can't get cookies). So RXI is less dangerous than other types of XSS, but don't forget about SOP bypassing methods ;) (in particular using bugs in browser to bypass SOP).

And there are many others attacks vectors, than cookies stealing. Like XSS for remote controlling, redirecting (as I show in the post) for phishing and others attacks, and especially code execution as I said before. By code execution I mean that bad guys can execute malicious code in user's browser (while hiding behind other site) - it can be used for malware, spyware, viruses, trojans and exploits execution.

So number of attacks is limited for RHI/RXI, but still wide. Therefore this type of vulns are dangerous and web developers need to be aware of it.</description>
		<content:encoded><![CDATA[<p>Alex, in this case Same Origin Policy (SOP) prevent access to sibling documents (and attacker can&#8217;t get cookies). So RXI is less dangerous than other types of XSS, but don&#8217;t forget about SOP bypassing methods <img src='http://websecurity.com.ua/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  (in particular using bugs in browser to bypass SOP).</p>
<p>And there are many others attacks vectors, than cookies stealing. Like XSS for remote controlling, redirecting (as I show in the post) for phishing and others attacks, and especially code execution as I said before. By code execution I mean that bad guys can execute malicious code in user&#8217;s browser (while hiding behind other site) - it can be used for malware, spyware, viruses, trojans and exploits execution.</p>
<p>So number of attacks is limited for RHI/RXI, but still wide. Therefore this type of vulns are dangerous and web developers need to be aware of it.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>від: Alex</title>
		<link>http://websecurity.com.ua/1049/#comment-39176</link>
		<pubDate>Sun, 17 Jun 2007 07:09:09 +0000</pubDate>
		<guid>http://websecurity.com.ua/1049/#comment-39176</guid>
					<description>Malicious code doesn't have access to sibling documents in the frameset because of Single Origin Policy, nor to cookies. That limits the number of attacks which are possible with such XSS.</description>
		<content:encoded><![CDATA[<p>Malicious code doesn&#8217;t have access to sibling documents in the frameset because of Single Origin Policy, nor to cookies. That limits the number of attacks which are possible with such XSS.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>від: MustLive</title>
		<link>http://websecurity.com.ua/1049/#comment-39163</link>
		<pubDate>Sat, 16 Jun 2007 23:20:21 +0000</pubDate>
		<guid>http://websecurity.com.ua/1049/#comment-39163</guid>
					<description>Yes, Alex, Remote HTML Include (RHI) is perfect phishing tool :-). Using a frame in a frameset of other site (for malicious purposes) is hole by design. But in case of malicious purposes this become a real security hole. It is Abuse of Functionality by WASC classification (for RHI), or it is Abuse of Functionality + XSS (for RXI).

In case of Remote XSS Include (RXI) it is possible to execute malicious code in browser when user is at another site (so attack is hidden). Two mentioned  redirectors are just for an example, that bad guys can redirect visitors. But others attacks are possible, so on the whole it is code execution vulnerability.</description>
		<content:encoded><![CDATA[<p>Yes, Alex, Remote HTML Include (RHI) is perfect phishing tool <img src='http://websecurity.com.ua/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> . Using a frame in a frameset of other site (for malicious purposes) is hole by design. But in case of malicious purposes this become a real security hole. It is Abuse of Functionality by WASC classification (for RHI), or it is Abuse of Functionality + XSS (for RXI).</p>
<p>In case of Remote XSS Include (RXI) it is possible to execute malicious code in browser when user is at another site (so attack is hidden). Two mentioned  redirectors are just for an example, that bad guys can redirect visitors. But others attacks are possible, so on the whole it is code execution vulnerability.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>від: Alex</title>
		<link>http://websecurity.com.ua/1049/#comment-37747</link>
		<pubDate>Fri, 15 Jun 2007 23:04:13 +0000</pubDate>
		<guid>http://websecurity.com.ua/1049/#comment-37747</guid>
					<description>This Remote HTML Include just hijacks a frame in a foreign frameset, doesn't it? Perfect phishing tool. And a funny one, because it's not a bug, it's by design. Good catch!</description>
		<content:encoded><![CDATA[<p>This Remote HTML Include just hijacks a frame in a foreign frameset, doesn&#8217;t it? Perfect phishing tool. And a funny one, because it&#8217;s not a bug, it&#8217;s by design. Good catch!
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
