Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Evolution of Web-based worms
Daniel Hanson, 2005-10-20

The Myspace Web worm used a simple vulnerability and XSS to propagate, and it might be a sign of things to come.

Comments Mode:
Evolution of Web-based worms 2005-10-21
assurbanipal
Ok, default-deny is better than default-permit.
But the real problem here is this: Why should I bother to filter HTML, which should supposedly serve *only* presentation purposes, and be aware of intricate security implications?
Who the hell devised Javascript in the way we know it now? THAT's the problem.
We are dealing with standards and technologies that are difficult to grasp and fully understand, and almost nobody strive to find KISS (Keep It Simple, Stupid!) solutions.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/364/32569#32569
Evolution of Web-based worms 2005-10-22
Angel (1 replies)
Re: Evolution of Web-based worms 2005-10-31
Author - DPH
Evolution of Web-based worms 2005-10-23
squeak
(D)Evolution of programming 2005-10-25
Alexey Vesnin
extremely insightful 2005-10-31
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus