Monthly Archives: September 2014

Sina OAuth 2.0 Service Covert Redirect Web Security Bugs (Information Leakage & Open Redirect)

  Sina OAuth 2.0 Service Covert Redirect Web Security Bugs (Information Leakage & Open Redirect)   (1) Domain: sina.com     “Sina (新浪) is a Chinese online media company for Chinese communities around the world. Sina operates four major business … Continue reading

Posted in 0Day, Covert Redirect Vulnerability, Website Testing | Tagged , , | Leave a comment

Godaddy Online Website Covert Redirect Web Security Bugs Based on Google.com

  Godaddy Online Website Covert Redirect Web Security Bugs Based on Google.com   (1) Domain: godaddy.com     “GoDaddy is a publicly traded Internet domain registrar and web hosting company. As of 2014, GoDaddy was said to have had more … Continue reading

Posted in 0Day, Covert Redirect Vulnerability, Website Testing | Tagged , , , , , , , , | Leave a comment

All Links to New York Times Articles Prior to 2013 Vulnerable to XSS Attacks

URLs to articles in New York Times (NYT) published before 2013 have been found to be vulnerable to an XSS (cross-site scripting) attack capable of delivering code to be executed in the context of the web browser.   Based on … Continue reading

Posted in IT News, Website Testing, XSS Vulnerability | Tagged , , , , , , , , , , , , | 1 Comment

Microsoft Live Online Service OAuth 2.0 Covert Redirect Web Security Bugs (Information Leakage & Open Redirect)

  Microsoft Live Online Service OAuth 2.0 Covert Redirect Web Security Bugs (Information Leakage & Open Redirect) (1) Domain: live.com     (2) Vulnerability Description: Live web application has a computer security problem. Hacker can exploit it by Covert Redirect … Continue reading

Posted in 0Day, Covert Redirect Vulnerability, Website Testing | Tagged , , , , , , , , , | Leave a comment

Сингапурский студент обнаружил серьезную уязвимость в OAuth и OpenID

OAuth и OpenID — очень популярные протоколы, которые совместно используются для авторизации и аутентификации. Приложение OAuth генерирует токены для клиентов, а OpenID предоставляет возможность децентрализованной аутентификации на сторонних сайтах, раскрывая персональные данные пользователей. Студент Ван Цзин (Wang Jing) с факультета … Continue reading

Posted in Computer Security | Tagged , , , , , , , , , , , , , , , , , , | Leave a comment