| Home : April 04 2014 Computer News : XSS flaw in popular video-sharing site enabled DDoS attack through visitors' browsers |
|
XSS flaw in popular video-sharing site enabled DDoS attack through visitors' browsers |
April 04, 2014
Attackers exploited a vulnerability in a popular video-sharing site to hijack users’ browsers for use in a large-scale distributed denial-of-service attack, according to researchers from Web security firm Incapsula.The attack happened Wednesday and was the result of a persistent cross-site scripting (XSS) vulnerability in a website that Incapsula declined to name, but said is among the top 50 websites in the world by traffic based on statistics from Amazon-owned firm Alexa.XSS flaws are the result of improper filtering of user input and can allow attackers to inject unauthorized script code into Web pages. If the code is stored permanently by the server and delivered to all users who view the affected page, the attack is considered persistent.To read this article in full or to leave a comment, please click here
Link: http://www.pcworld.com/article/2140320/xss-flaw-in-popular-videosharing-site-enabled-ddos-attack-through-visitors-browsers.html#tk.rss_all
|
|
|
|
|