post avatar

Bookmarklet of death: Domain hijacking without 0days

So we all know about cross-domain vulnerabilities that allow attackers to run code within the security context of the target domain. Typically, they are either a XSS bug on the server-side application, or a bug in the client (web browser plugin or web browser itself). Most of the times, these vulnerabilities require some type of interaction from the victim user. i.e.: being tricked to click on a link or visit a malicious page.

Now, most techies are familiar with bookmarklets. [...]

» more | » comments | » comments rss | posted by pagvac

test your web apps with websecurify application security testing runtime

The Others

from the creators of GNUCITIZEN we bring to you...

Random Posts

» more