Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email firstname.lastname@example.org
From: MustLive (mustlivewebsecurity.com.ua)
Date: Fri Jan 22 2010 - 13:08:51 CST
Hello participants of Full-Disclosure!
Yesterday I wrote English version of my article The future of XSS attacks
(http://websecurity.com.ua/3878/), which you can read if you interested in
In the article I talked about Cross-Site Scripting attacks where itís not
possible to use any tags and angle brackets. I listed attack vectors which
can be used in this case (automated and non-automated). And wrote about
current situation with modern browsers: in 2008 in Firefox 3 possibility of
attack via -moz-binding was removed (partly) and in IE 8, which released at
beginning of 2009, support of expression() was removed.
So I proposed my cross-browser solution for conducting of automated XSS
attacks in such conditions (when itís not possible to use any tags and angle
brackets) - with using of MouseOverJacking technique, which I already wrote
You can read the article The future of XSS attacks at my site:
Best wishes & regards,
Administrator of Websecurity web site
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/