Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

January 23rd, 2012, 08:09 GMT · By Eduard Kovacs

Hackers Prove EA, IGN, ImageShack, NY Times, Verizon Vulnerable

SHARE:

Adjust text size:


Internet Explorer 8 mitigates XSS attacks
Enlarge picture
A relatively new hacking collective, TeamHav0k, launched an operation called “#OP XSS” in which they try to find cross-site scripting (XSS) vulnerabilities in major websites. The first results of the operation came in and it turns out that a lot of important sites contain the flaw the hackers were looking for.

A Pastebin document reveals that websites such as the ones belonging to Verizon, Huffington Post, European Organization for Nuclear Research (CERN) , Electronic Arts (EA), IGN and New York Times contain some design flaws.

Some education institutions were also found to contain XSS security holes, including University of Illinois, Harvard, Yale and Rockefeller University.

Telecoms company Verizon, media hosting company ImageShack, value calculator and traffic estimator tool StatShow, Major League Gaming, and Dr Pepper complete the list.

Verizon's website contains XSS vulnerability
Enlarge picture
Even though XSS vulnerabilities are among the most common ones found in commercial websites, this doesn’t mean they’re not dangerous. Cybercriminals can rely on these weaknesses to execute their own malicious codes and cause damage to the virtual assets of unsuspecting Internet users.

Fortunately, some web browsers protect their customers against these attacks. For instance, Internet Explorer 8 and Internet Explorer 9 display a warning message to reveal that the page is modified to prevent cross-site scripting.

Google Chrome also mitigates the attack, but Opera and Mozilla Firefox fail to do so, leaving their users exposed.

Major websites, such as the ones mentioned before, should really put an effort into securing their domains against these common flaws. Because of the large numbers of visitors they have each day, hackers could use them for malevolent purposes.

Since TeamHav0k didn’t take advantage of the flaws, we can only assume that they’re a group of gray hats whose main purpose is to alert website administrators of existing vulnerabilities. We have tried to contact them to learn more about their mission and their purposes, so stay tuned for more details.

TELL US WHAT YOU THINK:

2,851 hits · 3 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


XSS Attacks Possible due to IE URI Encoding Flaw

Harvard and Oxford Universities Hacked by D35m0nd142

WordPress 3.3.1 Released to Fix XSS Vulnerability

phpMyAdmin 3.4.9 Closes Two Cross-Site Scripting Vulnerabilities

XSS Vulnerabilities Fixed in Fork CMS 3.1.7

READER COMMENTS:


Comment #1 by: mr.disclose on 23 Jan 2012, 10:53 UTC reply to this comment

lolz look at the first image , the url has been hidden from the URL but can be seen from the title bar ... lolz


Comment #2 by: DeadOnArrival on 23 Jan 2012, 12:05 UTC reply to this comment

Nice title bar on the redacted IGN picture...

Comment #2.1 by: Eduard Kovacs on 23 Jan 2012, 13:47 GMT

Thanks for pointing that out. It has been taken care of.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM