No account yet?
Home » HSC Research » Advisories » [HSC] Cross Site Scripting in Msn.com
[HSC] Cross Site Scripting in Msn.com E-mail
HSC Research Group - Advisories
Written by Hackers Center   
Saturday, 11 June 2005 21:59
Hackers Center Security Group (http://www.hackerscenter.com/)
Zinho"s Security Advisory

Desc: Multiple XSS holes in microsoft"s msn.com
Risk: Medium


I audited Msn.com for a couple of hours and I found an xss hole that
could lead anyone to steal passport account cookie or cookie for msn
chat.

It"s a month since my first attempt to contact someone at microsoft but
no response
received. If someone at microsoft reads this please contact me.
I hope you won"t let anyone to steal the so famous "passport" account
so easily.


Author:
Zinho is webmaster and founder of http://www.hackerscenter.com ,
Security research portal
Secure Web Hosting Companies Reviewed:
http://www.securityforge.com/web-hosting/secure-web-hosting.asp

zinho-no-spam @ hackerscenter.com
 

Security Services by HSC