|
|
Security Researcher Goes Public with MSN and Amazon Flaws - TechAmok
Security Researcher Goes Public with MSN and Amazon Flaws - [security] 04:58 PM EDT - Jul,02 2006 - post a comment Frustrated with what he calls a lack of response from Microsoft and
Amazon.com,
a security researcher has gone public with details of flaws on the two
companies' Web sites. The flaws could be used by attackers to steal "cookie"
data files that would allow them to access Amazon.com and MSN accounts, or to
display a fake login page that could be used in phishing attacks, according to
Yash Kadakia, the independent security researcher who discovered the flaws.
Although the cross-site scripting flaws he discovered are generally
considered to be low-risk problems, Kadakia's attack involves a technique called
CRLF (Carriage Return Line Feed) injection, which can be used in a more serious
and widespread attack, he said. Kadakia said he first notified Microsoft of the
problem about a year ago. But he said he was not taken seriously until late last
week, when he posted screen shots of the flaw being exploited on his Web site.
The Amazon.com flaw was discovered in December, but after some initial
discussions with the Web retailer, the vulnerability remained unpatched, Kadakia
said. "The conversations got dropped off somewhere," he said. A spokesman for
Microsoft's public relations agency said the flaws were now being investigated.
Amazon.com executives were unable to comment for this story.
|
|
Add your comment (free registrationrequired)
Short overview of recent news articles |
|
Jan,10 2026 Welcome to the Wasteland - Fallout (American TV series) fan video Jan,09 2026 GOOD LUCK, HAVE FUN, DON'T DIE Trailer 2 (2026) Sam Rockwell Jan,07 2026 NVIDIA Releases GeForce 591.74 WHQL Drivers with DLSS 4.5 Support Jan,07 2026 Predator: Badlands Exclusive Deleted Scene (2025) Jan,06 2026 Greenland 2: Migration - Official Trailer 3 (2026) Gerard Butler, Jan,05 2026 The Best Laptops of 2025 - For Gaming, Creators & Students! Jan,05 2026 Punkt Updates its Privacy-Focused Smartphone Jan,05 2026 Clicks Launches New Ways to Add a Physical Keyboard to Your Life Jan,05 2026 Building a PC for the First Time Jan,03 2026 Building a PC in 2026 Jan,02 2026 I want this phone so bad... - Samsung Galaxy Z TriFold Jan,02 2026 The Real Finewine Strikes Again: Ryzen 5600X, 5700X & 5800XT Revisit Jan,02 2026 Nokia N8 Symbian Re-Awakened With Passion Jan,02 2026 Europe Forces Apple to Open up More of iOS Jan,02 2026 Must have Privacy and Security Tweaks: 2026 Edition Jan,01 2026 How Did RAM Get So Expensive?! Dec,31 2025 GeForce RTX 5090 prices to soar to $5,000 as NVIDIA and AMD prep GPU Dec,30 2025 Hacker arrested for KMSAuto malware campaign with 2.8 million Dec,29 2025 Killer Whale - Official Trailer (2026) Virginia Gardner, Mel Dec,28 2025 NVIDIA Showed Me Their Supercomputer Dec,28 2025 2026 CPU Launches! AMD, Intel & NVIDIA: Buy Now or Wait? Dec,27 2025 Disable this Windows Feature that Secretly Eats Up RAM! Dec,27 2025 New Windows 11 vs Old Malware: Will it survive? Dec,27 2025 Samsung TriFold Durability Test: We found the limit Dec,26 2025 TRUST WALLET CONFIRMS SECURITY BREACH Dec,26 2025 Xiaomi 17 Ultra Leads And Samsung To Follow With A 10 Percent Price Dec,25 2025 Merry Christmas Gaming Insanity Dec,24 2025 Battlefield 6 - Official PS5 Features Trailer Dec,24 2025 NVIDIA GeForce Hotfix Driver 591.67 Released Dec,23 2025 Finally! A Battery That's Better Than Energizer and Duracell! Dec,22 2025 NVIDIA Killing Cheap 16GB Local AI GPUs? Dec,21 2025 Top 10 Movie Sequels of All Time Dec,21 2025 He Built a Privacy Tool. Now He's Going to Prison (Kone Rodriguez, Dec,20 2025 Insane Moves! B-Boy Shigekix vs. B-Boy Issin - Red Bull BC One World Dec,20 2025 9800X3D & RTX 5070 Ti Gaming PC - MSI Project Zero Done Right Dec,19 2025 The XG27AQWMG Sets a New Standard for 1440p OLED Dec,19 2025 OnePlus 15R Boasts Huge 7,400 mAh Battery Dec,19 2025 Motorola Refreshes moto g power for 2026 Dec,18 2025 NVIDIA GeForce 591.59 WHQL Driver Dec,18 2025 Are We Quitting YouTube Due To DRAM Apocalypse?
>> News Archive <<
| |
|