Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

November 11th, 2011, 19:03 GMT · By Eduard Kovacs

BLOG

Injector Hackers Reveal XSS Vulnerability on myOpenID

SHARE:

Adjust text size:

myOpenID is affected by an XSS vulnerability Enlarge picture - myOpenID is affected by an XSS vulnerability
A hacker called SeeMe showed that one of the largest independent OpenID providers is vulnerable to a cross-site scripting attack.

According to The Hacker News, the hacker made a proof-of-concept page just like in the case of the Speed Bit search engine we saw yesterday.

By making use of the flaw, attackers can steal a session ID of a valid customer which they can use to browse the website logged in as the victim.

“The session ID is very valuable because it is the secret token that the user presents after login as proof of identity until logout. If the session ID is stored in a cookie, the attackers can write a script which will run on the user's browser, query the value in the cookie and send it to the attackers,” the hacker said.

TELL US WHAT YOU THINK:

1,086 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Indian Hacker Finds Vulnerability in Speed Bit Search Engine

XSS Vulnerability Found in White House Website

XSS Vulnerability Found on AOL Energy Site

Symphony CMS Vulnerable to XSS and SQL Injection Attacks

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM