Italian develops first multi-site Web-mail worm

Posted on Saturday, July 14, 2007 @ 14:50:20 CEST in Security
by raven

nb1 writes:  
An Italian security researcher this week has developed the first Web-based e-mail worm capable of taking advantage of cross site scripting(XSS) vulnerabilities in multiple Web-mail services. Rosario Valotta described the new form of worm on his blog. The proof of concept, called Nduja Connection, could spread faster than one targeting only a single Web-mail provider, he said. E-mail worms propagate by extracting contact information from the address book of each infected user, and then sending out an e-mail with the worm payload to each contact -- a user needs only to open an infected e-mail message to spread the worm. Prior concept e-mail worms have been restricted to affecting only one e-mail client, however, the Nduja Connection worm has the potential to spread faster due to it's ability to infect users of four different Web e-mail clients.

Full story
click Related        click Share
News ©

Site Info

Last SeenLast Seen
  • hicuxunicorni...
  • neralex
Server TrafficServer Traffic
  • Total: 398,768,145
  • Today: 1,145
Server InfoServer Info
  • Feb 23, 2020
  • 12:34 am CET