Thursday, December 22, 2005

XSS on Significant Government Websites

Cross-site scripting is near and dear to my heart, and I think that the XSS Myspace worms and the occasional XSS-powered phishing attack are promoting them from "neat trick" to "annoying vulnerability." So, it's a little troubling when trivial (less than 40 seconds or so) experimentation reveals XSS on significant, high-profile, easily-Googleable US government websites.

Now I have to figure out how to deal with disclosing application vulnerabilities to powerful law enforcement agencies without getting shipped off to Poland. Hopefully, it will be easy and painless.

1 Comments:

Blogger Ann-Marie said...

Hi Honneee! Glad to see that you have working comments now. :-)

2:37 PM  

Post a Comment

Links to this post:

Create a Link

<< Home