/?pid=1198

Updated:12:30 PM EDT Apr 18


this is ggmania.com subsite Security Researcher Goes Public with MSN and Amazon Flaws - TechAmok

Security Researcher Goes Public with MSN and Amazon Flaws - [security]
04:58 PM EDT - Jul,02 2006 - post a comment

Frustrated with what he calls a lack of response from Microsoft and Amazon.com, a security researcher has gone public with details of flaws on the two companies' Web sites. The flaws could be used by attackers to steal "cookie" data files that would allow them to access Amazon.com and MSN accounts, or to display a fake login page that could be used in phishing attacks, according to Yash Kadakia, the independent security researcher who discovered the flaws.
Although the cross-site scripting flaws he discovered are generally considered to be low-risk problems, Kadakia's attack involves a technique called CRLF (Carriage Return Line Feed) injection, which can be used in a more serious and widespread attack, he said. Kadakia said he first notified Microsoft of the problem about a year ago. But he said he was not taken seriously until late last week, when he posted screen shots of the flaw being exploited on his Web site.

The Amazon.com flaw was discovered in December, but after some initial discussions with the Web retailer, the vulnerability remained unpatched, Kadakia said. "The conversations got dropped off somewhere," he said. A spokesman for Microsoft's public relations agency said the flaws were now being investigated. Amazon.com executives were unable to comment for this story.


Add your comment (free registrationrequired)

Short overview of recent news articles

Apr,18 2024 Radeon RX 5700 XT vs. 7700 XT, 2024 Revisit
Apr,18 2024 I Will Build You a PC Right Now!
Apr,17 2024 These games carry REAL security risks! BEWARE!
Apr,17 2024 Visible First to Offer Annual Payment Plan, with Discount up to 26%
Apr,17 2024 Is Coding Still Worth Learning in 2024?
Apr,17 2024 All New Atlas - Boston Dynamics
Apr,16 2024 The NEW Chip Inside Your Phone! (NPUs)
Apr,16 2024 XPS 14 vs 14" MacBook Pro - Apple just KILLED Intel!
Apr,15 2024 The Most 2024 Laptop - Razer Blade 14 Review
Apr,15 2024 NEVER install these programs on your PC... EVER!!!
Apr,14 2024 Use Live Translate on Galaxy S24 series to translate a call's
Apr,14 2024 I Tried a Non-Invasive Blood Sugar Watch. Miracle or Scam?
Apr,13 2024 Samsung Galaxy Ring - This Just Got Interesting
Apr,13 2024 Piracy Is Over Party - WAN Show April 12, 2024
Apr,13 2024 Conan O'Brien Needs a Doctor While Eating Spicy Wings
Apr,13 2024 Beatbox Jcob recreats every sound
Apr,13 2024 Intel is Gunning for NVIDIA
Apr,13 2024 Building a Budget DIY Home Surveillance System
Apr,12 2024 Lenovo Yoga Buyers Guide - What's the Best Thin and Light Laptop
Apr,11 2024 DARK MATTER Trailer (2024) New Sci-Fi Movies 4K
Apr,11 2024 How to Build a PC, the last guide you'll ever need! (2024 Update)
Apr,10 2024 Intel 300 CPU Review - The Pentium Replacement is Finally Here...
Apr,10 2024 Wubuntu, the Dubious Linux Windows
Apr,09 2024 A Lite Version Of Windows 11 To Be Released This Year
Apr,09 2024 This $150 Smartphone might be All You Need
Apr,09 2024 I Can't Believe These are Real - Reacting to Ridiculous PCs on
Apr,08 2024 A new video shows AirPower prototype charging an Apple Watch
Apr,08 2024 Google Deleting Incognito Data, Intel $7B Foundry Loss, $350+ Curved
Apr,08 2024 20 COOL GADGETS YOU SHOULD SEE
Apr,08 2024 New HTTP/2 vulnerability leaves servers in danger of devastating DoS
Apr,07 2024 3D Printed PC Fan Test: Does the Anti-Stall Ring Boost Performance?
Apr,06 2024 The Greatest GPU of All Time: NVIDIA GTX 1080 Ti & GTX 1080 2024
Apr,06 2024 Top NEW RELEASES on Netflix in APRIL 2024
Apr,05 2024 Magician vs Slow-Mo Camera (Skill Challenge)
Apr,05 2024 Re-Ranking All Current GPUs From Worst to Best (2024 Update)
Apr,04 2024 Ripple to ISSUE STABLE COIN utilizing XRP AUTO-Bridging Function
Apr,04 2024 HW News - Intel Battlemage Appears, Open Source GPU, Xbox Handheld
Apr,03 2024 Vivo X Fold 3 Pro Hands-On: The New Best Foldable Hardware
Apr,02 2024 OPNSense: Protect Your Home LAN With a Transparent Filtering Bridge
Mar,31 2024 Ultimate Guide to Virtualization: Run MacOS, Linux, and Windows all
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs