Evan Martin (evan) wrote in evan_tech,
Evan Martin
evan
evan_tech

universal pdf xss

Reportedly, any site hosting a PDF has an XSS exploit. The link has example XSS on Google, Microsoft, Bank of America(!), and others.

I anticipate a great flushing sound as every site removes all of their PDFs.

Update: it occurs to me that you could probably also fix this with a mod_rewrite (or equivalent) rule that 403's all parameters to PDF urls. Update2: supersat points out that won't work.

[via halkeye]
Subscribe

  • memcache job offers

    I get occasional recruiter spam that specifically calls out "my work on memcached". This is pretty funny because all I did was make some trivial…

  • application stack

    "Put yourself in 1995. I'm going to tell the you of 1995 that in 2010, there will be a software platform with the following properties:" Luis Villa…

  • bsd license advertising

    Did you know that the 3-clause BSD (that is, the one with the "advertising" clause stripped) license still has an advertising requirement? Read it…

  • Post a new comment

    Error

    default userpic
    When you submit the form an invisible reCAPTCHA check will be performed.
    You must follow the Privacy Policy and Google Terms of use.
  • 13 comments

  • memcache job offers

    I get occasional recruiter spam that specifically calls out "my work on memcached". This is pretty funny because all I did was make some trivial…

  • application stack

    "Put yourself in 1995. I'm going to tell the you of 1995 that in 2010, there will be a software platform with the following properties:" Luis Villa…

  • bsd license advertising

    Did you know that the 3-clause BSD (that is, the one with the "advertising" clause stripped) license still has an advertising requirement? Read it…