Please what is a XSS?
Cross Site Scripting, it's a pretty common JavaScript vulnerability that can be abused for cookie stealing and such. You can also re-direct to other sites. Let's say you use this XSS exploit, you use something like where it's vulnerable, mostly in the search function. Then you can just encode the link and make it look as if it's on Blizzards real site, then it re-directs to your phisher, and the victim is ****ed.
How do you find the XSS? Do you just enter js codes until you hit something or is there an actual method to getting them?
Well I tried it on WoW Guild Rankings :: WoWProgress - World of Warcraft Rankings and History and got a normal looking search page with alert("IT WORKS!")" :: World of Warcraft Rankings and History." /> at the top, but I dont think that's what I want lol
I don't suggest jumping into javascript and cookie jacking until you understand the language first, atleast to an extent. That was a beautiful find, a shame that it has been fixed.
Good luck,
-Ku
to bad it got fixed
LoL, you guys have no idea, Blizzard uses a php script that auto changes the link, its what banks use for online banking, paypal and ebay do it to. Shoot even I use it.
sad :/ .. we got a blizz on mmo ! who it is ... o.O ?