白帽子安全

白帽子文章
计算机安全
安全漏洞
网络攻击

© 白帽子安全 | Powered by LOFTER

Weather Channel Web Site Vulnerable to Reflected Cross-Site Scripting (XSS) 


Popular Weather Channel web site (Weather.com) has been found to be vulnerable to a reflected Cross-Site Scripting flaw, according to researcher Wang Jing’s research. The vulnerability lies in that Weather.com does not filter malicious script codes when constructing HTML tags with its URLs. This way, an attacker just adds a malicious script at the end of the URL and executes it.



“If The Weather Channel’s users were exploited, their Identity may be stolen,” Jing said via email. “At the same time, attackers may use the vulnerability to spy users’ habits, access sensitive information, alter browser functionality, perform denial of service attacks, etc.”



Weather.com’s monthly traffic may exceed 50-60 million visitors, which makes it a high-profile target.



Wang is a Ph.D student from School of Physical and Mathematical Sciences, Nanyang Technological University, Singapore.



During his research, Jing also noticed that 76.3 per cent of the 10,000 Weather.com tested links were vulnerable to XSS attacks.



The vulnerability lies in that Weather.com does not filter malicious script codes when constructing HTML tags with its URLs.



This way, an attacker just adds a malicious script at the end of the URL and executes it.






Related News:
http://www.scmagazine.com/the-weather-channels-xss
http://www.hotforsecurity.com/blog/weather-channel-flaw
http://packetstormsecurity.com/files/129288/weatherchannel-xss.txt
http://www.theregister.co.uk/2014/12/01/weather_channel_xss
http://tetraph.com/security/xss-vulnerability/the-weather-channel-exploit
http://ithut.tumblr.com/post/104659802158/whitehatview-the-weather-xss
http://www.inzeed.com/kaleidoscope/xss-vulnerability/the-weather-channel
http://w8sdz.tumblr.com/post/103849047220/weather-channel-web-site-vulnerable-to-reflected
http://sensorstechforum.com/75-of-the-websites-on-weather-com-vulnerable-to-cross-site-scripting-attacks/
https://www.facebook.com/websecuritiesnews/posts/699866823466824
http://www.cio.com/article/2853294/weathercom-fixes-web-application-vulnerabilities.html
http://www.pcworld.com/article/2853292/weathercom-fixes-web-application-vulnerabilities.html
http://www.computerworld.com/article/2852502/weathercom-fixes-web-app-flaws.html
https://www.secnews.gr/weather-channel-xss


评论
热度 ( 19 )
  1. 白帽子安全计算机网络技术 转载了此图片  到 测试想法
  2. 计算机网络技术文豆 & 文库 转载了此图片  到 行者路上有風有雨有彩虹
  3. 计算机网络技术文豆 & 文库 转载了此图片  到 绿意蛙鸣
  4. 计算机网络技术文豆 & 文库 转载了此图片  到 IT 计算机&信息网络 技术
  5. 计算机网络技术文豆 & 文库 转载了此图片
  6. 白帽子安全乡土情深 转载了此图片  到 湛天雲海碧波影
  7. 白帽子安全乡土情深 转载了此图片  到 文豆 & 文库
  8. 白帽子安全乡土情深 转载了此图片  到 竹意