this is ggmania.com subsite
|
Security Researcher Goes Public with MSN and Amazon Flaws - TechAmok
Security Researcher Goes Public with MSN and Amazon Flaws - [security] 04:58 PM EDT - Jul,02 2006 - post a comment Frustrated with what he calls a lack of response from Microsoft and
Amazon.com,
a security researcher has gone public with details of flaws on the two
companies' Web sites. The flaws could be used by attackers to steal "cookie"
data files that would allow them to access Amazon.com and MSN accounts, or to
display a fake login page that could be used in phishing attacks, according to
Yash Kadakia, the independent security researcher who discovered the flaws.
Although the cross-site scripting flaws he discovered are generally
considered to be low-risk problems, Kadakia's attack involves a technique called
CRLF (Carriage Return Line Feed) injection, which can be used in a more serious
and widespread attack, he said. Kadakia said he first notified Microsoft of the
problem about a year ago. But he said he was not taken seriously until late last
week, when he posted screen shots of the flaw being exploited on his Web site.
The Amazon.com flaw was discovered in December, but after some initial
discussions with the Web retailer, the vulnerability remained unpatched, Kadakia
said. "The conversations got dropped off somewhere," he said. A spokesman for
Microsoft's public relations agency said the flaws were now being investigated.
Amazon.com executives were unable to comment for this story.
|
|
Add your comment (free registrationrequired)
Short overview of recent news articles |
May,28 2025 SECRET CODE UPDATE for Samsung Galaxy Phone to Boost Performance & May,27 2025 WhatsApp is finally available on iPad May,27 2025 Simple Trick To Lower CPU Temperatures May,26 2025 Alma & The Wolf - Official Trailer (2025) Ethan Embry, Li Jun Li, May,25 2025 Change These Browser Security Settings NOW May,24 2025 I NEED AMD to Seize This Moment - RX 9060XT May,23 2025 Windows 98 with a G41 Core 2 Duo System May,23 2025 Disable These Windows Settings for Better FPS! May,20 2025 I Got the Golden GPU from Dubai May,19 2025 Windows 10 emergency update KB5061768 fixes BitLocker boot loops - May,19 2025 2025 AUDI S5 AVANT // 0-100 100-200 TOP SPEED POV & SOUND May,18 2025 Jurassic World Rebirth - Official 'Alert' Teaser Trailer (2025) May,18 2025 F1 25 and F1 The Movie hand in hand May,17 2025 Everyone is Cooling Their PC Wrong May,16 2025 M5 KILLER? Testing the MERCEDES E63S AMG! May,16 2025 Samsung Fully Reveals 5.8mm-Thick Galaxy S25 Edge May,16 2025 Apple Intros New Accessibility Apps, Plus Accessibility "Labels" May,16 2025 Americana - Official Trailer (2025) Sydney Sweeney, Halsey, Simon May,16 2025 Aston Martin x Apple CarPlay Ultra - Next generation of automotive May,15 2025 Google TAG deleted 23,000+ YouTube channels in January, February, May,14 2025 NVIDIA GeForce Game Ready 576.40 WHQL Driver Released May,13 2025 F1 - Official Trailer #2 (2025) Brad Pitt, Damson Idris, Kerry May,11 2025 The Old Guard 2 - Official Trailer (2025) Charlize Theron, KiKi May,11 2025 I think I know why Ryzen 9000 Series CPUs are Dying...(!) May,10 2025 Is Windows Defender good enough in 2025? May,09 2025 AMD Adrenalin 25.5.1 Driver Released for Doom: The Dark Ages May,09 2025 Ripple SEC Grip OVER, XRP Freedom of USE, Market MODE BULL RUN May,08 2025 "Is x86 Actually Screwed?" ft. Wendell of Level1 Techs - May,07 2025 Android's New Design Guidelines Leaked May,06 2025 Grand Theft Auto VI trailer #2 May,05 2025 Microsoft's Dirty Secret: Your Old PC is Now Trash! May,04 2025 No Noise Cancelling? GOOD. Unboxing the nwm One Headphones & First May,04 2025 NEW! 2025 Audi S5 (367hp) | 0-258 km/h acceleration May,02 2025 Bugatti Bolide vs Nurburgring. 1825 HorsePower Insanity May,01 2025 This will be the largest tech Yard Sale EVER! Insanely low prices on May,01 2025 Skoda Kodiaq RS 245 // 0-100 100-200 TOP SPEED POV & SOUND May,01 2025 Disable or Uninstall Windows Recall to Protect Your Data Privacy May,01 2025 A new Alternative to Nextcloud? OpenCloud presented and local Apr,29 2025 NVIDIA GeForce Hotfix Driver 576.26 Available Apr,28 2025 2025 Porsche 911 992.2 GTS T HYBRID | SOUND 0-100 100-200 200-300 &
>> News Archive <<
| |
|