November 14th, 2012

The Difference Between A Vulnerability And A Moron Using Google Services Trying To Phish Your Password

1276202472_ce7e194cf2_o

Today, The Next Web covered a post about a potential XSS “vulnerability” on Google’s app and gadget hosting services used on Google-hosted domains. Of course, more people piled on, as a “hacker” in Bulgaria released a “proof of concept” showing this “vulnerability.” Bunk. → Read More

September 20th, 2011

Skype Aware Of XSS Vulnerability In iOS Apps, “Working Hard To Fix” It

skype xss

If you’re using Skype for iOS on your iPhone or iPod touch, consider yourself warned: a cross-site scripting vulnerability looms in the “Chat Message” window in version 3.0.1 and earlier versions.

The hole allows attackers to execute malicious JavaScript code that runs when a victim views a chat message, enabling theft of information, including a user’s address book (see video below).

Skype… → Read More