|
HSC Research Group -
Advisories
|
|
Written by Hackers Center
|
|
Saturday, 11 June 2005 21:59 |
Hackers Center Security Group (http://www.hackerscenter.com/) Zinho"s Security Advisory
Desc: Multiple XSS holes in microsoft"s msn.com Risk: Medium
I audited Msn.com for a couple of hours and I found an xss hole that could lead anyone to steal passport account cookie or cookie for msn chat.
It"s a month since my first attempt to contact someone at microsoft but no response received. If someone at microsoft reads this please contact me. I hope you won"t let anyone to steal the so famous "passport" account so easily.
Author: Zinho is webmaster and founder of http://www.hackerscenter.com , Security research portal Secure Web Hosting Companies Reviewed: http://www.securityforge.com/web-hosting/secure-web-hosting.asp
zinho-no-spam @ hackerscenter.com
|