Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Fixes and Improvements

May 17th, 2012, 09:05 GMT · By

CyberZeist Finds XSS on Intel.com and Baidu.com

SHARE:

Adjust text size:

XSS on Baidu.com, China's largest search engine site
Enlarge picture
A hacker known as CyberZeist has found that the website of Baidu, the largest search engine in China, and one of Intel, the world renowned semiconductor chip maker, contain cross-site scripting (XSS) vulnerabilities.

We have explained the risks posed by such security holes numerous times, so this time we’ve let the hacker himself detail the dangers that lie behind apparently simple flaws.

“These two XSS are known as Non-Persistent XSS flaws. Though they have low risk factor, but if they are unresolved, this security hole could help a remote attacker to steal accounts by cookie-hijacking,” CyberZeist said.

“Also the attacker can easily Social Engineer any victim visiting the site into using a crafted URL like www.intel.com/about/[redacted] to steal its account or even trick the site admin to use the same URL, leading to overtaking the whole website!”

He also warns that in certain circumstances, the successful exploitation of such XSS vulnerabilities can lead to “bulk email disclosure.”

XSS on Intel.com
Enlarge picture
The hacker provided us with a proof-of-concept and screenshots that demonstrate his findings. Although the representatives of both companies have been notified regarding the existence of the vulnerabilities, so far they’ve failed to address the issues.

On Monday, we reported that a hacker found an XSS flaw on one of the subdomains of the website owned by the US Department of Defense (DOD). As it turns out, the same weakness has also been identified independently by CyberZeist.

Unlike Gambit, who also discovered the vulnerability, this hacker decided to report it to the administrators of dod.mil.

“I have reported it and got the reply that they are gonna rectify it,” he told us.

Well, NASA has begun fixing the large number of weaknesses that affect its websites, so it’s about time that the US government did the same.


2,035 hits · 2 comments
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


XSS and Redirect Bugs Found on DOD.mil and Military.com

Albanian Copyright Office and Australian Department of Education Sites Breached

Torrent Site Rewards Hacker for Finding XSS Flaws (Exclusive)

Hacker Finds XSS on Torrent and US National Institutes of Health Sites

Gambit Identifies XSS Flaw on Federal Trade Commission Site

READER COMMENTS:


Comment #1 by: Allen Kolster on 17 May 2012, 09:38 UTC reply to this comment

This guy is like on a marathon against US government!


Comment #2 by: Amar Irani on 18 May 2012, 20:31 UTC reply to this comment

lol... he is the same guy from CIA Hacks!
Wondering what will he do next!

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM