Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Stored XSS Vulnerability in Amazon (or How to hack Amazon with a book) (drwetter.eu)
138 points by borski on Dec 17, 2010 | hide | past | favorite | 12 comments


Just replicated the Stallown3d!1 one, it's still there.

Actually a useful link to have; I've had some difficulty convincing people in the past that this sort of injection is a big deal and that's a convenient, harmless way to prove the point.


Doesn't that mean you only need to control http://ha.ckers.org/s.js (or similar) rather than write a book?


This has to be the funniest XSS hack of all time.


The Bobby Tables of literature


This is fantastic! Great find. It reminds me a little of the idea of pen and paper attacks, like this http://news.ycombinator.com/item?id=1721494

But writing a book as an attack vector is certainly epic.


Couple of $$, Createspace. Bait-y title. Merry xmas!


Couldn't do it w/o logging in, until I copied the url from the author's picture.

http://www.amazon.com/XSS-Attacks-Scripting-Exploits-Defense...


Now THAT would be an elaborate hack to pull off. Obviously Amazon never thought of that! Between this and the magic goggles, this week is turning out to be so interesting.


That is an epic XSS hack. I think they won.


Possibly fixed?

I'm not seeing this vulnerability now via Mac FireFox 3.6.12 or Safari.


It seems so, I'm not seeing this with Internet Explorer. The Book Preview does not work at all in Opera :-(


ha.ckers is down. :(




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: