[WEB SECURITY] XSIO - Cross Site Image Overlaying

Pritesh Parekh priteshp at Yodlee.com
Tue Sep 11 18:28:57 EDT 2007


Hi Sven:

Good paper! I agree with the team that this is not new but I think this
issue may be often overlooked and this paper might gain some more
awareness. All the best for your computer science coursework!

Thanks,
Pritesh 

-----Original Message-----
From: Sven Vetsch / Disenchant [mailto:sven.vetsch at disenchant.ch] 
Sent: Monday, September 10, 2007 12:32 PM
To: websecurity at webappsec.org
Subject: [WEB SECURITY] XSIO - Cross Site Image Overlaying

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi everyone,
I wrote a paper about an attack type I call "XSIO - Cross Site Image
Overlaying". It's about something which I think many of you have already
done but I wasn't able to find something written about it and even I
don't think, that most of the people out there are aware of how big the
impact of something like this could be. But just read the paper if
you're interested in hear some more about it :)

http://www.disenchant.ch/blog/xsio-cross-site-image-overlaying/81

Regards,
Sven

- --

sent by Sven Vetsch / Disenchant

www.disenchant.ch

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFG5ZuX8luv3I4ijh0RAnoOAJ9wcsDfdd3YV1Lc6lDIbcffGdzZfACgnq/G
pcaYn+al0UNHxnSMX+XEJxU=
=XNf1
-----END PGP SIGNATURE-----

------------------------------------------------------------------------
----
Join us on IRC: irc.freenode.net #webappsec

Have a question? Search The Web Security Mailing List Archives: 
http://www.webappsec.org/lists/websecurity/

Subscribe via RSS: 
http://www.webappsec.org/rss/websecurity.rss [RSS Feed]


----------------------------------------------------------------------------
Join us on IRC: irc.freenode.net #webappsec

Have a question? Search The Web Security Mailing List Archives: 
http://www.webappsec.org/lists/websecurity/

Subscribe via RSS: 
http://www.webappsec.org/rss/websecurity.rss [RSS Feed]



More information about the websecurity mailing list