Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Editor Blogs > Security

June 5th, 2012, 18:21 GMT · By

BLOG

Hacker Reports XSS Flaws to US Department of Energy, NASDAQ, NASA

SHARE:

Adjust text size:


XSS on US Department of Energy website Enlarge picture - XSS on US Department of Energy website
The hacker that goes by the name of Gambit has identified non-persistent cross-site scripting (XSS) vulnerabilities on a number of important sites, including the US Department of Energy (doe.gov), Minute Workers, NASDAQ, US Office of the Secretary of Defense (osd.mil), NASA (starbrite.jpl.nasa.gov), Canadian media company CBC, and EA.

Non-persistent cross-site scripting vulnerabilities are not as dangerous as persistent ones, but that doesn’t mean webmasters should not address them to protect their customers from attacks that rely on social engineering.

In some cases, Gambit has identified more than one vulnerable subdomain.

The hacker told Softpedia that all the security holes were reported to the affected sites’ webmasters, but so far none of them had responded to his notifications.

However, one of the affected domains, the one Electronic Arts has dedicated to the Burnout Paradise game, displays a “server maintenance” notification, which may indicate that some work is being done to the site.

Update. According to the hacker, NASA has responded to his notifications. The report has been forwarded to the agency's security team. 

XSS VULNERABILITIES IDENTIFIED BY GAMBIT ON VARIOUS SITES - PHOTO GALLERY:

TELL US WHAT YOU THINK:

1,414 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Hacker Confronts Microsoft on Lack of XSS Filters in MSN Explorer (Exclusive, Updated)

Big Bang Theory Inspires Hacker to Find SQL Injection Flaw on ORNL Site

Torrent Site Rewards Hacker for Finding XSS Flaws (Exclusive)

CyberZeist Finds XSS on Intel.com and Baidu.com

Hacker Finds XSS on Torrent and US National Institutes of Health Sites

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM