Cross-site scripting vulnerability could have been exploited by phishers
Cross-site scripting vulnerability could have been exploited by phishers
R E L A T E D   C O N T E N T
ADVERTISEMENT

Phishing flaw catches Xbox 360 site

Microsoft patches www.xbox360.com after phishing attack warning

Robert Jaques, vnunet.com 25 May 2005
ADVERTISEMENT

Microsoft has patched a potentially dangerous flaw on its www.xbox360.com website after security experts warned the software giant of a cross-site scripting vulnerability which could be exploited by hackers to launch phishing attacks.

The vulnerability could be used by web criminals to gather personal and confidential information, such as email address, home address and credit card number, from innocent consumers wishing to pre-order Microsoft's forthcoming gaming console.

IT security firm Finjan Software said that it provided Microsoft with full technical details on 19 May, including proof-of-concept, in order to assist the company with the fix.

Within 12 hours of Finjan's report Microsoft had removed the flaw from its website, which is no longer exposed to this specific vulnerability.

Shlomo Touboul, chief executive and founder of Finjan Software, said: "This discovery is another example of our co-operation with Microsoft and other leading software vendors to fix vulnerabilities before they are exploited by the hacking community."

See also:

Firefox toolbar provides information on a website's hosting locationSoftware cuts down on scams by spotting fraudulent URLs  26 May 2005
Lack of backwards compatibility for games such as Halo 2Different chip architecture means games need to be recompiled  18 May 2005

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C#, GUI Developer – Fixed Income – Investment Bank. My client is seeking a strong C# ASP.Net developer to join their Fixed Income area and operate within one of the top tier investment banks in ... more >
| Computer People
Technical Project Manager / SDLC West London, £75k - (Software Development, SDLC), RUP Serious opportunity for hands on Technical Project Manager to join a leading blue chip organisation based in an easily accessible area of ... more >
| Computer People
C# Developer - Nottingham 4 Month Contract Market Rates I have an exciting opportunity for a C# ASP.NETDeveloper working for an established client within Computer People. Working from their offices in Nottingham you’ll be providing ... more >
| JAM Recruitment
Job Ref: AS/20356/TAX Package: c£60,000.00 + Bonus + Benefits Location: Middlesex Job type: International Assignment / Global Mobility / Expatriate Tax Manager Position type: Permanent Hours: Full-time Contact name: Andy Shaw Contact Company: JAM Mobility ... more >
More job opportunities