译文:英特尔安全中心爆跨站漏洞

安全
跨站脚本漏洞影响到英特尔产品安全中心网站。可成功地利用IFRAME注射,任意重定向和cookie会话劫持。

英特尔安全中心是家提供英特尔产品安全问题咨询的机构。“通过安全警告和安全告示,英特尔一直在致力于改善我们的客户计算环境的安全。

因为它们的出现,我们将致力于迅速解决该问题,并提供解决问题建议,”在主页网站上的一条消息说明。

http://security-center.intel.com上的跨站脚本漏洞是一个名叫Methodman的黑客发现的。这个安全漏洞似乎影响到所有咨询网页,可以使用个人发布的恶意软件,进行钓鱼或各种不同的恶意攻击。

Methodman公布了代码的和截图证明,演示攻击者如何注入任意的IFRAME网址或引发重定向到另一个链接。此外,劫持cookie会话或开恶意玩笑也是可能的。作者写完这篇文章时,该漏洞仍然存在。
  

原文如下:
  Intel Security Center Lacks Security
  A cross-site scripting flaw affecting the Intel Product Security Center website has been disclosed. Successful exploitation allows for rogue iframe injection, arbitrary redirection and session cookie hijacking.
  The Intel Security Center is home to advisories regarding security issues that affect Intel products. "Intel is focused on improving the security of our customers computing environments. We are committed to rapidly addressing issues as they arise, and providing recommendations through security advisories and security notices," a message on the website's main page notes.
  The XSS weakness on http://security-center.intel.com has been discovered by a hacker going by the nickname of Methodman. The flaw seems to affect all advisory pages and can be used by ill-intentioned individuals to distribute malware, launch phishing campaigns, or instrument various malicious attacks.
  The proof-of-concept code and screenshots published by Methodman demonstrate how poor URL validation allows an attacker to inject an arbitrary iframe or trigger a redirection to another link. In addition, revealing session cookies or launching rogue alerts is also possible. At the time this article was being writtten, the flaws were still active.

责任编辑:王文文 来源: 黑客基地
相关推荐

2023-11-20 13:06:52

2019-05-15 14:16:03

英特尔ZombieLoad漏洞

2011-01-10 08:58:47

英特尔The Chase F窗口

2014-12-03 10:34:31

2014-04-03 14:23:02

英特尔统一固件管理套件

2010-06-17 15:40:40

英特尔数据中心架构

2014-04-02 15:10:05

英特尔智能设备创新中心

2015-07-27 14:57:07

Rackspace英特尔OpenStack开发

2013-08-06 09:33:28

英特尔数据中心淘汰

2010-09-18 16:24:55

2010-05-10 14:33:52

TBB 3.0并行编程

2009-07-30 11:43:32

2013-09-19 13:26:56

英特尔数据中心服务需求

2009-02-28 22:13:18

万亿次英特尔数据中心

2011-12-14 19:01:20

英特尔

2010-05-06 09:22:28

AMD皓龙英特尔至强

2021-10-29 05:37:37

英特尔谷歌云数据中心芯片

2010-04-29 10:42:08

数据中心能效策略

2012-05-07 09:41:58

英特尔云计算云安全
点赞
收藏

51CTO技术栈公众号