744 karma · joined November 24, 2012
www.listnerd.com/lists?letter=</script><script>alert(document.cookie);</script>
Direct direct memory access access?
I found a cross site scripting vulnerability in Bing.com that was kind of hilarious. Searching for:
</script><script>arbitrary js</script>
in the main search box would execute the code on the results page. I mean, holy shit. I could not believe it. I emailed their whitehat service and they fixed it but I never received a bounty.After about 2 minutes of looking, I've just found that nic.io (or just io.) basically lets you type arbitrary html into the search boxes. Chrome's built in XSS auditor catches any scripts you put in there, but (at least) Firefox doesn't.
Check it out:
http://io./cgi-bin/whois?query=%3Ca%20href=%22%22%3E%3Cu%3EA...
If you load it in Firefox (or any browser without an XSS auditor) it'll pop an alert, otherwise you'll just see the image I loaded and a link I inserted.
This is ridiculous.
Definitely worth a watch
The technical complexity of getting a seamless Wifi connection 30,000 feet above ground warrants its $12.00 in my opinion.
You might find the following interesting: http://www.ladyada.net/make/mintyboost/icharge.html