Targeting Spam > US-ASCII XSS part 2

[ha.ckers.org security lab] Jeremiah Grossman and I spent some time looking at the exploit that Kurt Huwig found using malformed ASCII chars to bypass filters. We were able to actually turn this into HTML that will run, without using open and close angle brackets.

Some related posts from Technorati and Google.

ha.ckers.org security lab: Jeremiah Grossman (via Cosmos)

Dancho Danchev - Mind Streams of Information Security Knowledge!: "Cross-Site Scripting Worms and Viruses - The Impending Threat and the Best Defense" also argues on Samy being the fastest worm, though single-packet UDP worms, according to a research on the "Top Speed of Flash Worm" by "Simulating a flash version of Slammer, calibrated by current Internet latency measurements and observed worm packet delivery rates, we show that a worm could saturate 95% of one million vulnerable hosts on the Internet in 510 milliseconds. A similar worm using a TCP based service could 95% saturate in 1.3 seconds. (via Cosmos)

Website Security, and Web Application Security News: The URL uses SSL to encrypt information transmitted to and from the site, and a valid 256-bit SSL certificate is presented to confirm that the site does indeed belong to PayPal; however, some of the content on the page has been modified by the fraudsters via a cross-site scripting technique (XSS)." (via Cosmos)

Reflected tags on Technorati: Blog, ,