Hello participants of Mailing List.

Recently I wrote new article Using of the sites for attacks on other sites
(http://websecurity.com.ua/4322/). And yesterday I posted brief English
version of it to Full-disclosure mailing list

In this article I told about conducting of attacks on other sites via Abuse
of Functionality vulnerabilities. Here is some important quotes:

This attack method can be of use when it's needed to conduct invisible CSRF
attack on other site (to not show yourself), for conducting of DoS and DDoS
attacks and for conducting of other attacks, particularly for making
different actions which need to be made from different IP. For example, at
online voting, for turning of hits of counters and hits of advertising at
the site, and also for turning of clicks (click fraud).

Note, that this DoS attack is possible to use for attacks on redirectors,
which I wrote about in my articles Redirector’s hell and Hellfire for

Also at conducting of DoS attacks it's possible to use several such servers
at once and so to conduct DDoS attack. In such case these servers will be
appearing as zombie-computers. I.e. botnet will be made from not home
computers, but from web servers (which can have larger capacities and faster
connections). So these vulnerabilities can lead to appearing of new class of
botnets (with zombie-servers).

