C O M M O N M Y T H
“Phishing and XSS only affect applications on the public
Internet.”
XSS bugs can affect any type of web application, and an attack against an
intranet-based application, delivered via a group email, can exploit two forms
of trust. First, there is the social trust exploited by an internal email sent
between colleagues. Second, victims’ browsers will often trust corporate web
servers more than they do those on the public Internet — for example, with
Internet Explorer if a computer is part of a corporate domain, the browser will
default to a lower level of security when accessing intranet-based applications.
Chapter 12
■
Attacking Other Users
395
70779c12.qxd:WileyRed 9/14/07 3:14 PM Page 395
Do'stlaringiz bilan baham: |