Alibaba Taobao (taobao) Covert Redirect Security Vulnerability - TopicsExpress



          

Alibaba Taobao (taobao) Covert Redirect Security Vulnerability Based on Apple Domain: taobao “Taobao is a Chinese website for online shopping similar to eBay and Amazon that is operated in China by Alibaba Group.” (Wikipedia) “With around 760 million product listings as of March 2013, Taobao Marketplace is one of the world’s top 10 most visited websites according to Alexa. For the year ended March 31, 2013, the combined gross merchandise volume (GMV) of Taobao Marketplace and Tmall exceeded 1 trillion yuan.” (Wikipedia) Alexa ranking 7 at 7:30 pm Wednesday, 16 September 2014 (GMT+8). Those vulnerablities were reported to Alibaba in 2014 and have been patched by the security team by today (just checked). Name was listed in the hall of fame by Alibaba. security.alibaba/people.htm?id=2048213134 Vulnerability Discover: Wang Jing, Division of Mathematical Sciences (MAS), School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore. tetraph/wangjing/ Poc Video: https://youtube/watch?v=jhnaoB_eus0&feature=youtu.be Blog Detail: securityrelated.blogspot/2015/01/alibaba-taobao-taobaocom-open-redirect.html https://youtube/watch?v=jhnaoB_eus0
Posted on: Thu, 22 Jan 2015 11:15:04 +0000

Trending Topics



Recently Viewed Topics




© 2015