Benjamin Flesch = definitely rocks.”> Alexa Top50 XSS, possible? (Update) ~ mybeNi websecurity, web security and hack stuff.

web securitymybeNi websecurity

Alexa Top50 XSS, possible? (Update)

March 28th, 2007

Hello World, for a future project I’ll release within the next two weeks, I am going to search XSS vulnerabilities in Alexa’s 50 most popular homepages out there.

My approach will be documented here, let’s see how far I’ll get :)

UPDATE: Only 19 homepages left!

5 Responses to “Alexa Top50 XSS, possible? (Update)”:

  1. Philipp Says:

    Yeah it’s possible


  2. hanicker Says:

    No post, non party.. XD… Can I ask you if you use some software (like Acunetix)? Maybe only intelligence can find these XSS..


  3. beNi Says:

    hanicker: Nope, I dont use any software. In my opinion, for finding XSS in these pages, you’re better off doing it manually ;-)
    Additinally, scanners like Acunetix are too noisy (just my 2 cents)


  4. hanicker Says:

    Can I ask you if all xss you found are usefull for cookie grabbing?


  5. beNi Says:

    Of course! Stealing cookies is the simplest thing you can do with XSS. All vulnerabilities mentioned here are on the “real” domain e.g. not on any useless subdomain.


Leave a Reply


Google Traffic (7 days)

250
200
150
100
50
196
190
190
199
219
173
119
38.107.191.103