Network World
Thursday, August 28, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

Worst Article Ever

0

I read the article that this story links to and spent the next few minutes laughing and yelling at my screen. The description of how the XSS works "by sending the user to a different site, that steals their session cookie", that is wrong! The 'other' site doesn't have access to your cookies!!

Then in the paragraph after the example they say that this approach is used in SPAM emails too! "A user is sent an email saying that their account has been compromised and they need to click a link fix it, but the link directs them to a different evil page." That isn't a XSS that is a Phishing SPAM!

And where in the article does it suggest a fix? It doesn't. NW, did you actually read this article?

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Latest software headlines from Network World:

Oracle integrates CRM On Demand with Siebel

Mozilla extension would tap into typed commands

iPhone fantasy football draft tools

Microsoft tweaks anti-piracy check for Windows XP

Platinum Solitaire for iPhone

  1   2   3   4   5   6   7   8   9  10  next 

Advertisement: