Christian BoyLove Forum #53925
|
While reading the post below, which offers a link to an image on a well known web site, it occurred to me that it is likely that a number of people aren't aware of the risks involved in visiting web sites, even trusted ones.
Due to the rise of cross site scripting (XSS) vulnerabilities, it is no longer safe to assume that a web site you are visiting is benevolent based only on the fact that it is a trusted web site. Due to poor coding practices that will take many years to correct, an incredible number of web sites are vulnerable to cross site scripting. If you visit a malicious link to an otherwise trusted site (cnn.com, theregister.co.uk, etc.) and that site is vulnerable to cross site scripting, then that normally harmless web site could run malicious scripts on your system thanks to the malicious link used to get you to that site. In the past, there have been talks on certain forums about using similar hacking techniques in an attempt to gather information on users of our forum and other bl forums. Therefore, it is important to protect yourself. Don't base your decision to follow a link on whether the site linked to is trusted, but also factor in how much you trust the person who provided the link. To minimize the risk of malicious scripts being run on your system, disable java script and turn it on only when you need it for a site you trust and got to through a means other than following a link in an email or on a message board. Note: There's nothing wrong with the link previously provided. Neither have I ever seen this type of attack attempted on this board. But it's only a matter of time. |