Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Many 'Hacker Safe' Web Sites Found Vulnerable

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Editorials & Other Articles Donate to DU
 
OhioChick Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jan-17-08 08:18 PM
Original message
Many 'Hacker Safe' Web Sites Found Vulnerable
Computer scientists say that more than 60 sites certified as safe by McAfee's ScanAlert service have been vulnerable to cross-site scripting attacks.

By Thomas Claburn
InformationWeek
January 17, 2008 03:00 PM


More than 60 Web sites certified to be "Hacker Safe" by McAfee's ScanAlert service have been vulnerable to cross-site scripting (XSS) attacks over the past year, including the ScanAlert Web site itself. While the XSS hole in the ScanAlert site and others have been addressed, some apparently have not been, leaving visitors potentially vulnerable to client-side attacks.
Joseph Pierini, director of enterprise services for the ScanAlert "Hacker Safe" program, maintains that XSS vulnerabilities can't be used to hack a server.

Still, Kevin Fernandez and Dimitris Pagkalos, two computer scientists who maintain XSSed.com, a site that has been tracking XSS vulnerabilities since February 2007, provided InformationWeek with a list of 62 Web sites certified as "Hacker Safe" on which XSS holes have been reported. The list includes brookstone.com, cafepress.com, cduniverse.com, gnc.com, mysecurewallet.nl, petsmart.com, and sportsauthority.com, among other familiar brands.

The XSSed.com site tracks whether reported XSS flaws have been fixed, but such information may not be accurate if the site making the repairs, or the initial discoverer of the hole, fails to report the fix. While XSSed.com data doesn't specifically correlate the presence of a "Hacker Safe" badge on a site with the time when an XSS vulnerability was active -- the certification could have been withdrawn while the hole was present and then reinstated -- security researchers report that some sites currently certified as "Hacker Safe" also are currently vulnerable to XSS attacks.

http://www.informationweek.com/news/showArticle.jhtml?articleID=205900444
Printer Friendly | Permalink |  | Top

Home » Discuss » Editorials & Other Articles Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC