Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

October 4th, 2010, 10:57 GMT · By

Persistent XSS Bug Found on Amazon

SHARE:

Adjust text size:


Persistent XSS vulnerability found in Amazon new product form
Enlarge picture
A persistent cross-site scripting (XSS) weakness discovered on Amazon, allowed potentially rogue merchants to generate product listings capable of hijacking session cookies.

The vulnerability was discovered and reported to the XSSed Project on September 30 by a security researcher calling himself SeeMe.

The problem is located in the "Title" field of the form used to publish new products in Amazon's catalog. Therefore, exploiting it requires a $39.99 Pro Merchant subscription.

Insufficient validation of data passed through the vulnerable field allows potential attackers to inject malicious code in the resulting product page.

The researcher created a proof-of-concept listing, which prompted an alert box with the visitor's session cookie, but he could just as easily have it sent to a remote website under his control.

The rogue product page was discoverable through Google, but it could have also been used to craft a credible email-based phishing attack.

"Fraudsters can create a new Pro Merchant account with stolen credit/debit card details and verify their identity by a public telephone or unregistered (in some jurestictions) pay-as-you-go mobile phone number," explained Dimitris Pagkalos, co-founder of the XSSed Project.

"Unsuspecting Amazon users are susceptible to malicious XSS attacks that target personal and financial information.

"If the fraudsters use a popular keyword in the XSS attack vector, an even larger number of Amazon users could be infected," he warned.

There is currently no confirmation that the vulnerability was fixed, but according to Pagkalos, Amazon's security team reacts quickly to such reports.

XSS vulnerabilities are very common, but the majority only allow for so called "reflected" attacks, which imply tricking users into opening malformed URLs.

XSS weaknesses that can be exploited to inject unauthorized code into actual pages, like in this case, are known as "persistent" and can be very dangerous.

Two such vulnerabilities were used to launch XSS worms on both Twitter and Orkut recently, where users of the social networking sites would become infected just by viewing a maliciously crafted message.

TELL US WHAT YOU THINK:

1,044 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Vodafone Websites Riddled with XSS and SQL Injection Vulnerabilities

Two XSS Vulnerabilities Found on PayPal Websites

XSS Worm Hits Orkut

XSS Bug Wreaks Havoc on Twitter

XSS Weakness Found on Visa USA Website

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM