Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Persistent XSS Vulnerability in White House Website filter_list
Author
Message
Persistent XSS Vulnerability in White House Website #1
[Image: Untitled.png]

IMAGE LINK: http://evilking.0adz.com/Untitled.png
Alexander Fuchs, A German Security Researcher Discover Persistent XSS Vulnerability in Official website of White House. He said "The petition system is vulnerable. Every Petition i start or join will execute my code. I could join all petitions and my code will be executed on all users who visit the petition system."

The XSS Demo is here: https://wwws.whitehouse.gov/petitions/!/...y/WxgwM7DS
Advisory: http://vulnerability-lab.com/get_content.php?id=308



source: http://thehackernews.com/2011/11/persist...white.html


SAY THANKS!!OR BUY ME BEERCool

Reply

RE: Persistent XSS Vulnerability in White House Website #2
why did you post it twice?
(This post was last modified: 11-05-2011, 07:43 AM by Skullmeat.)
Pierce the life fibers with your drill.

Reply

RE: Persistent XSS Vulnerability in White House Website #3
(11-05-2011, 07:42 AM)1234Darkmaster Wrote: why did you post it twice?

which one?

Reply

RE: Persistent XSS Vulnerability in White House Website #4
oh nvm that was AOL Biggrin Biggrin
Pierce the life fibers with your drill.

Reply

RE: Persistent XSS Vulnerability in White House Website #5
Don't leech Things from skidforums

skidforums

(remove the point)
Feel free to PM me.


Reply

RE: Persistent XSS Vulnerability in White House Website #6
(11-05-2011, 10:40 AM)Proskill Wrote: Don't leech Things from skidforums

skidforums

(remove the point)
hey dude

i think i am not leech it from skidforums

in my post in end i tell you that source is thehackernews.com
and i can not found it on hackforums

Reply

RE: Persistent XSS Vulnerability in White House Website #7
First off, there is higher security for the white house than you can pull off to cover your tracks (this is down to the fact that the government has official rights to monitor everything associated with any incoming and outgoing connection to there electronically based systems and databases)

Secondly, Just attempting to do this would result in big consequences, this is not recommended at all unless you have permission to do so.

Thirdly, Highly illegal and stupid. There's finding vulnerabilities, and there is executing vulnerabilities.
[Image: 600x.gif]
[username], If you need assistance private message me

Reply