Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Cross Site Scripting is a Big Problem [bug fixed] (bigheadlabs.com)
9 points by staunch on April 20, 2007 | hide | past | favorite | 2 comments


I guess it's a good thing there's no authentication on that site.


Any domain cookies for .bigheadlabs.com are vulnerable, which could be a real problem (Wordpress admin maybe?).

Domains are so cheap now that I almost always buy one for every project (even hacks) these days, partially just to isolate potential XSS issues.

I didn't mean to imply anything disparaging towards you, this kind of annoying stuff pops up even at Google. It's so easy to miss a spot, especially on quick hacks.

Thanks for creating that site, it's an awesome contribution.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: