Peaches Posted September 29, 2009 Report Share Posted September 29, 2009 Sept. 28, 2009 Reddit attacked by XSS exploit The Reddit social news aggregator was reportedly the subject of a cross site scripting attack where just hovering over a comment message could cause a logged in user to post rogue comments. The XSS attack appears to exploit a vulnerability which allows JavaScript code to be inserted into Reddit comments. According to a thread on Reddit, a user named Empirical created some JavaScript code which, if copied and pasted into the address bar, would reply to all the comments on a Reddit page, while another user named "xssfinder" created a proof of concept which could run JavaScript code by hovering over a comment. Xssfinder then decided to combine the two pieces of code and tested it in a sub-Reddit called "proofofhax". From there, the XSS exploit spread over Reddit. Read more at Heise security - http://www.h-online.com/security/Reddit-At...t--/news/114337 Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.