Tunnelling HTTP Traffic Through XSS Channels
by Ferruh Mavituna - Wednesday, 11 July 2007.
An XSS Channel is an interactive communication channel between two systems which is opened by an XSS attack. At a technical level, it is a type of AJAX application which can obtain commands, send responses back and is able to talk cross-domain.

The XSS Shell is a tool that can be used to setup an XSS Channel between a victim and an attacker so that an attacker to control a victimís browser by sending it commands. This communication is bi-directional.

To get the XSS Shell to work an attacker needs to inject the XSS Shellís JavaScript reference by way of an XSS attack. The attacker is then able to control the victimís browser. After this point the attacker can see requests, responses and is able to instruct the victimís browser to carryout requests.

Download the article in PDF format here.

Spotlight

Most popular Android apps open users to MITM attacks

Posted on 21 August 2014.  |  An analysis of the 1,000 most popular free Android apps from the Google Play store has revealed a depressing fact: most of them sport an SSL/TLS vulnerability that can be misused for executing MITM attacks, and occasionally additional ones, as well.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Thu, Aug 21st
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //