LastPass security hole (cross site scripting)
Posted: Wed Mar 02, 2011 1:14 pm
this is just a copy/paste of a message I just posted on Avast forums, after reading a few reports. Not sure if all this has been mentioned here already... anyway:
lastpass cross scripting vulnerability revealed:
http://www.theregister.co.uk/2011/03/01 ... e_xss_bug/
https://grepular.com/LastPass_Vulnerabi ... nt_Details
forum thread:
http://forums.lastpass.com/viewtopic.php?f=12&t=60559
lastpass response:
http://blog.lastpass.com/2011/02/cross- ... ility.html
http://blog.lastpass.com/2011/03/conten ... ented.html
... I guess - if we don't take LP recent fixes into account - people using FF NoScript on any FF version or simply using FF4 (CSP implementation https://wiki.mozilla.org/Security/CSP/Specification ) are protected.
lastpass cross scripting vulnerability revealed:
http://www.theregister.co.uk/2011/03/01 ... e_xss_bug/
https://grepular.com/LastPass_Vulnerabi ... nt_Details
forum thread:
http://forums.lastpass.com/viewtopic.php?f=12&t=60559
lastpass response:
http://blog.lastpass.com/2011/02/cross- ... ility.html
http://blog.lastpass.com/2011/03/conten ... ented.html
... I guess - if we don't take LP recent fixes into account - people using FF NoScript on any FF version or simply using FF4 (CSP implementation https://wiki.mozilla.org/Security/CSP/Specification ) are protected.