Showing posts with label XSS. Show all posts
Showing posts with label XSS. Show all posts

Friday, 20 February 2015

Cisco Warns Of Attacks On The ASA VPN Software


Cisco warns organizations for attacks on the ASA software allowing attackers credentials can get their hands on for VPN connections or malware can spread. The vulnerability is in the Clientless SSL VPN software. The software provides ASA-administrators the ability to customize the appearance of the Client SSL VPN portal.

A vulnerability in the "customization framework" which the adjustments are made allow a remote attacker without login details the contents of the Clientless SSL VPN portal adjust. This makes it possible to steal login details, cross-site scripting (XSS) and other web attacks to perform and distribute malware instance. Once a VPN portal is compromised adaptations of the persistent attacker.

Restarting the server or changing the ASA Software custom objects will does not remove. The leak was unveiled late last year and patched. Yet who now find attacks rather abuse the vulnerability. In addition, on the Internet also exploit code appeared. Cisco has in the warning information also given how compromised VPN portal can be recognized.

Tuesday, 10 February 2015

HackerOne Bug Fixes Serious Platform For Bug Reports


HackerOne, the platform for reporting vulnerabilities in various software projects and applications, has itself had to deal with a serious vulnerability that attackers may have access to unpublished bug reports from other investigators could get.

Cross Site Scripting (XSS) issue exists was caused by the way HackerOne the "\" character tried left harmless. Therefore could allow an attacker to execute code on a webpage, which could help again in a phishing attack, says researcher Daniel LeCheminant who discovered the problem.

He suspects that an attacker could also add arbitrary HTML to bug reports in order to gain unauthorized access to the bug reports and data from other researchers. It is the first time that an XSS problem was discovered in HackerOne. A day after LeCheminant administrators had informed the vulnerability was corrected and he got a reward of $ 5,000. An amount that is only for serious bugs reserved .