On 8/27/06, Denis Jedig <seclists@xxxxxxxxxxxx> wrote:
Are there any documented cases on "serious" (i.e. not for scientific research or fun, but profit) desinformation or propaganda campaigns using XSS for their purposes? Some weird US pre-election stuff maybe?
Does this count? http://news.netcraft.com/archives/2006/06/16/paypal_security_flaw_allows_identity_theft.html Regards, Brian _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/