After months of extensive research, San Jose California-based WhiteHat Security has unmasked a flaw in one of the Web's cornerstone protocols which places all e-commerce sites, as well as scores of Internet users, in jeopardy.
The attack, dubbed Cross-Site Tracing (XST), involves a method whereby a programmable engine or common client side scripting language, such as JavaScript, accesses and obtains Web authentication credentials on a target system regardless of how well the information is stored and protected. This in turn can be used by a hacker to assume the identity of a victim on an array of sites ranging from Web mail, to online banking, to auction sites.
|