XSS für Einsteiger: Spaß mit eplus.de

Hanno's Blog

Monday, March 12. 2007

XSS für Einsteiger: Spaß mit eplus.de


XSS on eplus.de
Note: This is just a short form of a german article I posted today. E-Plus is a big german mobile telephony provider. I've found a bunch of XSS together with Alexander Brachmann (responsible disclosure, all reported to E-Plus before, probably more to come
Weblog: Hanno's blog
Tracked: Mar 12, 19:13

Display comments as (Linear | Threaded)

Anscheinend reagiert E-Plus auf Druck. Zumindest kommt jetzt auch bei den noch nicht gefixten URLs ein 404 - Page not found und kein JavaScriptaufruf mehr.
#1 Pat (Homepage) on 2007-03-14 10:32 (Reply)
Na ja, eigentlich hatte E-Plus auch weitaus mehr und komplizierter Dinge zu fixen als das vorgestellte. Keine Ahnung, wie weit sie bis jetzt gekommen sind.
#2 Alex (Homepage) on 2007-05-01 01:23 (Reply)
Cooles Tut, Hanno. Aber die Infos sind mittlerweile leider veraltet. Deine Beispiele funktionieren nicht (mehr).
#3 Tuck on 2007-06-04 12:51 (Reply)

Add Comment

E-Mail addresses will not be displayed and will only be used for E-Mail notifications.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.



This blog is written by Hanno Böck. Unless noted otherwise, its content is licensed as CC0.

You can find my web page with links to my work as a journalist here.

I am also publishing a newsletter about climate change and decarbonization technologies.

The blog uses the free software Serendipity and is hosted at schokokeks.org.

Hanno on Mastodon | Contact / Imprint | Privacy / Datenschutz