Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

February 25th, 2012, 13:27 GMT · By Eduard Kovacs

BLOG

Freedom: TESCO and Comet Sites Exposed to Hackers (Exclusive)

SHARE:

Adjust text size:

XSS in TESCO's site Enlarge picture - XSS in TESCO's site
Freedom, the grey hat hacker we met a few days ago, returns with some interesting finds. He managed to identify a couple of cross-site scripting (XSS) vulnerabilities in the official sites of the popular retailers TESCO and Comet.

The first security hole was identified on TESCO’s site, tesco.com.

“This was again a very easily found issue but could be abused. For a site of its popularity you believe the security would be even in the slightest secure. I have seen multiple scripts (free) with better secuirty than TESCO,” the hacker told us.

The grey hat provided screenshots to prove the existence of the flaws on both sites.

“This had a very easily got around filtering system which blocked you from inputting more than 30 chars but if you searched something ‘prohibited’ it would then allow you to search over the restricted number of chars and also input quite simple html which could easily be abused,” Freedom said about Comet’s website.

He also discovered some minor flaws in scripting on the sites of Henleys (henleys.co.uk) and Chanel (chanel.com).
FILED UNDER:
XSS
Xomet
Tesco
Freedom

XSS VULNERABILITIES - PHOTO GALLERY:

TELL US WHAT YOU THINK:

998 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Yves Saint Laurent, ABC and Sky Sports Vulnerable to Hackers (Exclusive, Updated)

AOL.com and Ask.com Vulnerable to XSS Attacks

Ivy League Universities Targeted by Hackers in OpIvy

XSS Flaw in Skype Shop May Allow Hackers to Steal User Accounts

TeamHav0k Finds XSS in British, French, and US Government Sites

READER COMMENTS:


Comment #1 by: Nick on 26 Feb 2012, 17:15 UTC reply to this comment

Hire the guy?

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM