快猫短视频

Security danger found in web postings

A security risk found to affect Hotmail and other commercial sites may highlight a new wave of internet vulnerability

A new way to highjack internet sites to attack individual web users, with just a single line of code, has been discovered by a US researcher.

The trick uses Cross Site Scripting (CSS), a technique identified by security experts in 1997. This exploits the ability of internet sites and web applications to contain embedded scripts and links to other web pages in order to execute dangerous code.

The new trick was discovered by Jeremiah Grossman, a consultant for US company Whitehat Security. He found that just one line of code was enough to fool many web sites into running rogue code.

Among these sites was Microsoft鈥檚 popular web email service Hotmail, as well as other undisclosed commercial web sites. The administrators of these sites were informed and created a fix for the problem before it was made public, but Grossman says that the vulnerability may be widespread.

鈥淲eb application developers and security engineers are urged to check and update their current HTML filters in all HTML-aware web applications,鈥 says Grossman in a security announcement. 鈥淭his includes web mail, on-line auctions, message boards, HTML chats and guest books.鈥

Clear and present danger

Some computer experts say that the flaw is serious but does not represent a major threat to most users because it involves targeting an individual. 鈥淐SS is certainly a problem,鈥 says David Litchfield, a security consultant with US firm @Stake. 鈥淏ut I don鈥檛 suppose that many people have been affected by it so far.鈥

Others are more worried. Gunter Ollman, of Internet Security Systems, believes that the ever-increasing functionality of many web sites will make this sort of problem more common in the future. 鈥淎s everything starts joining together, the likelihood of this happening will increase, as will the ease of doing it,鈥 he told 快猫短视频.

The scam uncovered by Grossman employs Cross Site Scripting to execute code that would normally be blocked by a web server鈥檚 security filters. By encoding a customised piece of code and a link to an external site into a web site posting, Grossman found it is possible to steal files from an unwitting user鈥檚 personal computer.

The technique could potentially be used to grab cookies, the files that allow someone to return to a site without a password and can give access to email accounts or online credit card details.

More from 快猫短视频

Explore the latest news, articles and features