| |||||||
| Slashdot RSS RSS news feed directly from Slashdot. |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| | #1 (permalink) | |
| Rebecca Bug writes "Several Web sites (Wired, eWEEK, The Washington Post) are reporting on Dan Kaminsky's Toorcon discussion of a serious security risk introduced when major ISPs serve ads on error pages. Kaminsky found that the advertising servers are impersonating, via DNS, hostnames within trademarked domains. 'We have determined that these injected servers are, in fact, vulnerable to cross-site scripting attacks. Since these servers are being injected into your trademarked domains, their vulnerability can be used to attack your users and your sites,' Kaminsky said, identifying EarthLink, Verizon and Quest among the ISPs." Read more of this story at Slashdot. More... | ||
| | | |
| Sponsored Links |
![]() |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Ars Technica // Canadian ISP tests injecting content into web pages | Gizmo | Ars Technica RSS | 0 | 10-December-07 11:20 PM |
| Ars Technica // Major ISPs to begin taking payments for delivery of commercial e-mail | Gizmo | Ars Technica RSS | 0 | 07-June-07 02:20 PM |
| Slashdot // Apple Mac OS X Update For 17 Vulnerabilities | Gizmo | Slashdot RSS | 0 | 26-May-07 10:00 PM |
| Slashdot // Big Day For Browser Vulnerabilities | Gizmo | Slashdot RSS | 1 | 20-October-04 02:55 PM |
| Slashdot // More Diebold E-Voting Vulnerabilities | Gizmo | Slashdot RSS | 0 | 22-September-04 02:14 PM |