Stories
Slash Boxes
Comments
typodupeerror delete not in

+-   Major ISPs Injecting Ads, Vulnerabilities Into Web on Saturday April 19 2008, @04:30PM Rebecca Bug

Submitted by Rebecca Bug on Saturday April 19 2008, @04:30PM
security
Rebecca Bug writes "Several Web sites (Wired, eWEEK, WaPo) are reporting on Dan Kaminsky's Toorcon discussion of a serious security risk introduced when major ISPs serve ads on error pages. Kaminsky found that the advertising servers are impersonating, via DNS, hostnames within trademarked domains. "We have determined that these injected servers are, in fact, vulnerable to cross-site scripting attacks. Since these servers are being injected into your trademarked domains, their vulnerability can be used to attack your users and your sites," Kaminsky said, identifying EarthLink, Verizon and Quest among the ISPs."
submission

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
Don't vote -- it only encourages them!