No XSS warning here.

Ask for help about NoScript, no registration needed to post
nagan
Senior Member
Posts: 340
Joined: Thu Mar 26, 2009 11:05 am

No XSS warning here.

Post by nagan »

http://emuasylum.com/forums/z/rs/files. ... 1&s=103809

Displayed as only a rapidshare link.Or was it really a harmless one?
Dreams are REAL possibilities. Pursue them with zest and you can make them HAPPEN!
You are GOD.Realize THAT!
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: No XSS warning here.

Post by Giorgio Maone »

There's no XSS that I can see there.
It just seems a quite accurate phishing copy, even though you can tell it's not rapidshare by just checking the address bar, which is the bare minimum against pishing.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7 (.NET CLR 3.5.30729)
nagan
Senior Member
Posts: 340
Joined: Thu Mar 26, 2009 11:05 am

Re: No XSS warning here.

Post by nagan »

Hi,
Could you tell the difference between an xss attack and the one above (for educative interest)? Earlier I used to get NS xss warnings on similiar sites which had a similiar non Rapidshare addresses and trying to phish.
If a guy is half asleep ,he is gone!
Dreams are REAL possibilities. Pursue them with zest and you can make them HAPPEN!
You are GOD.Realize THAT!
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: No XSS warning here.

Post by Giorgio Maone »

nagan wrote:Hi,
Could you tell the difference between an xss attack and the one above (for educative interest)?
If Rapidshare has a XSS vulnerability, an attacker could show you an identical page with a rapidshare.com URL in your address bar.
At that point, even if you're full awake, you can't tell the difference.
Furthermore, if you're already logged in, or you enabled the "remember me" feature, or you've got the browser's password-completion feature enabled, your credentials are gone even if you're not shown the page (e.g. if it's loaded in an hidden IFRAME), let alone interact with it.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7 (.NET CLR 3.5.30729)
Post Reply