Cross Site Scripting on Whois

Considering how many sites scrape or use Whois info, I’d say that a hole like that is pretty massive for hackers.

Cross Site Scripting on Whois

comments below

Here’s a very nice XSS find by Klaus:

Most domain registrars (have yet to find one that does) will not filter what you put on your REGISTRANT CONTACT INFO and WILL allow the script tag!

Considering how many sites scrape or use Whois info, I’d say that a hole like that is pretty massive for hackers.

bookmark this article:
  • reddit
  • digg
  • netscape
  • del.icio.us

Leave a Reply

You must be logged in to post a comment.