Skip to main content

Netscape hacked via an XSS attack!

Acunetix scans for Cross-Site Scripting vulnerabilities preventing website defacement

 

London, UK – 28 July, 2006 – Netscape.com, an online social media website, has been hacked through a cross-site scripting (XSS) vulnerability in their recently launched news service. It is reported that the attack was launched by fans of Digg.com, a competing social networking website. The hackers used ...the XSS vulnerability to inject their own JavaScript code into the homepage and other pages on the site.

 

The hack was discovered by Finnish security vendor (F-Secure), during their research work around cross-site scripting vulnerabilities on social networking sites. Digg fans used cross-site scripting attacks to display JavaScript pop-up alerts with "comical" messages aimed at redirecting visitors to their site. Fortunately no malicious code was injected. Netscape released a statement yesterday afternoon stating that the vulnerability had been patched and that visitors are once again safe.

 

Acunetix Web Vulnerability Scanner automatically audits web applications and checks whether these applications are secure from exploitable vulnerabilities to such hack attacks as cross site scripting. Although Netscape has now fixed the flaw, an automated check of Netscape’s website (using Acunetix WVS) could have prevented this attack and saved the company from denting its reputation and the subsequent loss of customer trust. Furthermore, hackers could have injected code aimed at stealing personal customer data rather than defacement. Most hackers, nowadays, attack websites because of the payoff from stealing such sensitive data as credit cards and social security numbers.

 

Acunetix provides free audit to help companies determine the security of their websites

 

Enterprises who would like to have their website security checked can register for a free audit by visiting www.acunetix.com/security-audit. Participating enterprises will receive a summary audit report showing whether their website is secure or not. Summary reports will be delivered within five business days of submission.

Your IP address:

3.145.58.90

All-in-one protection for Microsoft 365

All-in-one protection for Microsoft 365

FREE Hyper-V & VMware Backup

FREE Hyper-V & VMware Backup

Wi-Fi Key Generator

Generate/Crack any
WEP, WPA, WPA2 Key!

Network and Server Monitoring

Network and Server Monitoring

Follow Firewall.cx

Cisco Password Crack

Decrypt Cisco Type-7 Passwords on the fly!

Decrypt Now!

Bandwidth Monitor

Zoho Netflow Analyzer Free Download

Free PatchManager

Free PatchManager

EventLog Analyzer

ManageEngine Eventlog Analyzer

Security Podcast

Hornet-Security-The-Swarm-Podcast

Firewall Analyzer

zoho firewall analyzer