Household Name LG Scores Poorly in Defending against XSS Attacks
Household Name LG Scores Poorly in Defending against XSS Attacks
  • By Kim Yu-na (yuna@koreaittimes.com)
  • 승인 2014.06.19 18:52
  • 댓글 0
이 기사를 공유합니다

SEOUL, KOREA - Reflected (or non-persistent) cross-site scripting (XSS) vulnerabilities have been detected on the websites of LG Electronics, LG ELIT (the website of The LG Sangnam Library) and LG Science Land (run by the LG Sangnam Library). XSS, a malicious code injection attack, could cause the victim’s browser to execute the injected malicious script through the browser’s search function.



The Open Web Application Security Project (OWASP), a non-profit charitable organization dedicated to improving the security of software, has named reflected XSS, a type of computer security vulnerability typically found in Web applications, as one of the three most common Web security threats. The Ministry of Security and Public Administration (MOSPA) of South Korea has already suggested preventive measures against XSS attacks in its 2012 cyber security guidelines. However, LG, one of the nation’s largest conglomerates, stopped short of observing the guidelines.

In a cross-site scripting (XSS) attack, a malicious script is inserted into the website’s search box or address bar. XSS enables the attacker to inject arbitrary web script or HTML into various websites via the kwd parameter and then to trick users into clicking on the malicious link. Thus, the malicious code could be distributed and spread as widely as possible.

To top it off, XSS attacks could lead to large-scale security breaches, such as the leak of sensitive personal data (including financial information) and keylogging, depending on the purpose of the malicious codes.

Microsoft’s Internet Explorer 6 and 7 and all the versions of Firefox are vulnerable to XSS attacks. Users of Internet Explorer 8 or higher should enable the Internet Explorer 8 XSS filter so as to foil XSS attacks.

Website operators should either show search results after deleting “<” , “>” or choose not to show any search result when they spot “<”, “>,” Lockdown, a white hacker group, advised. XSS-vulnerable websites should also inform their visitors of the fact that they fell victim to XSS attacks and should stay on high alert to prevent secondary damage, Lockdown added.

The XSS-vulnerable websites of LG Electronics, LG ELIT and LG Science Land are high- traffic, so myriads of users could fall prey to XSS attacks if the status quo in Web security persisted.


댓글삭제
삭제한 댓글은 다시 복구할 수 없습니다.
그래도 삭제하시겠습니까?
댓글 0
댓글쓰기
계정을 선택하시면 로그인·계정인증을 통해
댓글을 남기실 수 있습니다.

  • #1206, 36-4 Yeouido-dong, Yeongdeungpo-gu, Seoul, Korea(Postal Code 07331)
  • 서울특별시 영등포구 여의도동 36-4 (국제금융로8길 34) / 오륜빌딩 1206호
  • URL: www.koreaittimes.com / m.koreaittimes.com. Editorial Div. 02-578-0434 / 010-2442-9446. Email: info@koreaittimes.com.
  • Publisher: Monica Younsoo Chung. Chief Editorial Writer: Kim Hyoung-joong. CEO: Lee Kap-soo. Editor: Jung Yeon-jin.
  • Juvenile Protection Manager: Yeon Choul-woong. IT Times Canada: Willow St. Vancouver BC, Canada / 070-7008-0005.
  • Copyright(C) Korea IT Times, Allrights reserved.
ND소프트