Prev | Current Page 392 | Next

Rich Cannings, Himanshu Dwivedi, Zane Lackey, and Alex Stamos

"Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions"


XSS via clickTAG
Popularity: 6
Simplicity: 9
Impact: 8
Risk Rating: 8
The flaw just mentioned may seem obvious, uncommon, and/or easily avoidable.
This is far from true. Flash has a special variable called clickTAG, which is designed for
Flash-based advertisements that help advertisers track where advertisements are
displayed. Most ad networks require advertisements to add the clickTAG URL parameter
and execute getURL(clickTAG) in their advertisements! A typical ad banner embed or
object HTML tags look like this:

Or this:
data=" http://adnetwork.com/SomeAdBanner.swf" width="640" height="480" >

380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404
zamykanie naczynek bielsko centralka Wczasy nad morzem oferty spa kierunki studiów