Browsing tag

Cross-site scripting (XSS)

Bug in LinkedIn allowed data to be stolen

Private profile data, like phone numbers and email addresses, could have been easily collected. According to information security experts, the flaw was found in LinkedIn’s widely used AutoFill plugin, which allows approved third-party websites to let LinkedIn members automatically fill in basic information from their profile — such as their name, email address, location, and where they […]

Security Researcher found vulnerabilities on the HP Website

The security expert Rafael Fontes Souza has discovered vulnerabilities in the website of HP (Hewlett Packard) and decided to explain concepts of code review to mitigate the risk of this failure and prevent future attacks. “I would like to make it clear, I am writing this report for educational purpose, I contacted HP Security-Team that […]