LinuxWorld shows off Web 2.0 hacks
LinuxWorld today played host to a demonstration of the vulnerabilities of Web 2.0, with SPI Dynamic's senior security engineer, Matt Fisher, offering some new examples of what criminals are doing online, armed with little more than a desktop browser. Cross-site scripting attacks are the number one online threat, according to the Mitre organisation, in part because they are so easy to do.
In particular, Fisher singled out social-networking sites. Because the site depends on user content, the site allows users to upload HTML code, and in most cases, any HTML code. Knowing this, Fisher said someone could put a malicious script code into a blog post where it would sit until someone came along and read it.
What bad could possibly happen from that, you might wonder? Fisher said that when someone in a corporate environment opens it, the attacker can then execute code inside the corporate perimeter on the internal network.