PCI Rock, WTH?
Security Awareness Programs can be a daunting task. It is not atypical to try to mix security awareness programs with some element of fun, such as humor with a message.
Security Awareness Programs can be a daunting task. It is not atypical to try to mix security awareness programs with some element of fun, such as humor with a message.
Earlier today Wesley Kerfoot reported on the Full Disclosure mailing list that a page in the Paypal.com domain is susceptible to a non-persistent reflected cross site scripting attack (XSS). While non-persistent XSS bugs are somewhat common, this is quite serious for a site like PayPal, where user accounts are linked directly to bank accounts, debit, or credit cards and payment can be made to third parties without any additional authentication after user access is gained.