Security Watch: Squatters Jumping Claims To Domain Names

Cross-Site Scripting Attacks

Several security researchers have been focusing in the last few weeks on "Cross-Site Scripting" vulnerabilities in various Web sites. A Russian research site has just revealed one of many in the PayPal site.

Consider this link:This is a link to the PayPal site, and a cursory examination of it, from left to right, will reveal it to be such.

But the link includes scripting instructions that redirect the page to a different site, in this case PCMag.com. This attack realizes more malicious potential when it is run in a frameset where the URL continues to display the paypal.com address but the window contains some other site's HTML.

Many security tools, including the Netcraft Toolbar, generically identify attacks such as these as cross-site scripting attacks. You can also identify many of them just by being more alert to URL contents and windows.



Comment on this article
Be the first to comment on this article.
Upcoming eSeminars

Data Protection Virtual Tradeshow
Cameron Crotty 50x50

Available On-Demand
Join Cameron Crotty and experts as they explore best practices and solutions needed to maintain a secure flow of data.
Available On-Demand
Security 2.0: Controlling Complexity
with Cameron Crotty. Sponsored by Symantec
Available On-Demand
Backup Exec 11d - The Gold Standard in Windows Data Recovery
with Frank Derfler. Sponsored by Symantec
Advertisement