Cross-site scripting (XSS) is a type of computer security vulnerability found in Web applications. XSS enables attacker to inject client-side script into Web pages viewed by other users. The expression "cross-site scripting" originally referred to the act of loading the attacked, third-party web application from an unrelated attack site, in a manner that executes a fragment of JavaScript prepared by the attacker in the security context of the targeted domain (a reflected or non-persistent XSS vulnerability). Lots of Indian websites are vulnerable to OWASP TOP-10 listed attack vectors that is cross site scripting abriviated as 'XSS'- attack.
Here is the Network 18's websites, which are vulnerable to Cross Site Scripting attack.
FOUNDED AND REPORTED BY-
INDRANIL BANERJEE (NULL_()_VOID)
CO-FOUNDER,
OPENFIRE-SECURITY.NET
1. In.com – top rated Indian website. Vulnerable to XSS attack Persistent as well as DOM based. Reported but not fixed yet.
3. Bitztech2.in.com – vulnerable to XSS not reported just published!!!
4. Ibnlive.in.com – Vulnerable to XSS and has others threats. Reported but not fixed yet.
5. Khabar.ibnlive.in.com – Vulnerable to XXS (Persistent). Has other vulnerabilities. Reported but not fixed yet.
6. Moneycontrol.com – N18 website!! Vulnerable to XSS (non-persistent). Have more vulnerability. Reported earlier but still not fixed.
7. Poweryourtrade.moneycontrol.com – Vulnerable to XSS. REOPORTED BUT NOT FIXED YET.
Here is the demonstration of the vulnerable Network 18’s websites. All are reported but still no action is taken by the concerned authority.
No harm is made on those websites by NULL_()_VOID ,it’s just a random testing result which might not harm those websites but can disrupt the reputation of those.
I have attached a pdf file also. Which was given by NULL_()_VOID to us. Please download it to know more.
DOWNLOAD :- http://www.mediafire.com/view/?bv7s89fnor1f3cr
FILE PASSWORD:- i-love-null-void
THANK YOU































