Security Holes Found in 25 "Verisign Trusted" Online Stores
Freedom, the grey hat hacker that in the past period identified a lot of cross-site scripting (XSS) vulnerabilities in some important websites, returns with other interesting finds. He discovered a number of 25 online shops from the United Kingdom containing XSS security holes.
The worrying thing is that all of the sites bare Verisign Trusted, Internet Shopping is Safe, Internet Delivery is Safe, Verified by Visa, and MasterCard SecureCode logos.
“25 of these big sites all run the same script and it was not hard to find them all using a home made ‘Google dork’. They try to filter the search on the main pages but then when you search for something that is well not there it then allows you to search again and this one has no limit to characters and very lil filtering,” the hacker told us. “A person with 5 mins of looking at XSS could make these sites fall to the knees and well do alot of damage to the reputations of these sites.”