Saturday, November 10, 2007

Severe XSS in Google and Others due to the JAR protocol issues

I had a few ideas in my mind about how the problem can be exploited in terms of Google. The first one was related to uploading a JAR archive on a public Google URL (docs, groups, etc). The second idea that I had was related to tricking the browser into believing that an external archive is located on the Google domain, possibly related to some kind

read more | digg story