:: LasT_CoFFiN Was Here ::

Gw orangnya aga gemuk, item (tau manis tau ga neh..!! hehe), disinilah Tempat Gw mencurahkan perasaan dan saling berbagi..!!

Tuesday, June 06, 2006

Yahoo! Mail XSS Vulnerability

Adivisory Name : Yahoo! Mail XSS Vulnerability
Release Date : 2006.04.21
Application : Yahoo! web-based email service
Test On : Microsoft IE 6.0
Discover : Cheng Peng Su(applesoup_at_gmail.com)

Introduction:

Yahoo! Mail is one of the Internet's most popular web based email solutions.

Details:

This vulnerability is resulted from the failure of Yahoo! Mail's filtering engine
to block "expression()" syntax in a CSS attribute using a comment to break up
expression, and the comment symbol( /* */ ) must be hex encoded so that we can
bypass the filter.

An example:

Hello

the injected code inside the CSS attribute is responsible for

-Getting cookies.
-Potential web-based e-mail worm.

Vender status:

2006.04.01 Informed the vendor.
2006.04.03 The vendor confirmed the vulnerability.
2006.04.XX The vendor patched the vulnerability. ( They patched it silently )

Original advisory:

http://applesoup.googlepages.com/yahoo_mail_xss.txt

1 Comments:

Blogger opt1lc said...

kang FS nya apa dunk,
add saya aja deh, opt1lc@yahoo.co.id

he,,he,,,

best regards

2:11 AM  

Post a Comment

<< Home