BugTraq
XSS on Yahoo Mail Nov 23 2005 05:44PM
Richard Fuchshuber (richardfuch yahoo com br) (2 replies)
RE: XSS on Yahoo Mail Nov 24 2005 02:50AM
Will Wesley (willwesleyccna yahoo de) (3 replies)
Re: XSS on Yahoo Mail Nov 25 2005 05:30PM
Steven Champeon (schampeo hesketh com) (1 replies)
Re: XSS on Yahoo Mail Nov 26 2005 12:00AM
Will Wesley (willwesleyccna yahoo de)
RE: XSS on Yahoo Mail Nov 24 2005 10:41PM
Richard Fuchshuber (richardfuch yahoo com br)
Re: XSS on Yahoo Mail Nov 24 2005 07:28PM
Jim Ley (jim jibbering com)

"Will Wesley" <willwesleyccna (at) yahoo (dot) de [email concealed]> wrote in message
news:20051124025004.32883.qmail (at) web26902.mail.ukl.yahoo.com. (dot) . [email concealed]

>This is not exactly a problem with Yahoo!, but rather
>a problem with the way browsers tend to render HTML
>when forced to deal with broken tags.

So it's a problem with Yahoo, as they allow the email, to write to places on
the screen that is not part of the email. I agree this is certainly down to
the liberalness of the browsers parser, but that doesn't mean yahoo can
ignore it, it's just a demonstration of how difficult a job it is for people
who want to accept arbitrary HTML to be secure for their user

Of course there is a pretty simple solution, which is to just use an IFRAME,
then there's no way the email to escape into the surrounding chrome.

Jim.

[ reply ]
Re: XSS on Yahoo Mail Nov 24 2005 01:23AM
Personal Account (jetflash hotpop com)


 

Privacy Statement
Copyright 2010, SecurityFocus