« October 2005 | Main | December 2005 »
While trying to use the ‘search’ feature on Digg, I realized that it is vulnerable to Cross Site Scripting (XSS). The search string is echoed back without proper output encoding. Example:

I haven’t checked to see if the comments or new story submission modules are affected – if they are, things could get pretty messy. I have contacted the Digg team about this, lets hope they fix it soon.
Update: They fixed it this morning.
According to this posting on the Full Disclosure mailing list, Papa John’s Pizza’s web-based e-mail system was not password protected for a while. They have since fixed the problem, but Google currently has the information in its cache. The following Google query will let you see these e-mails (click on the ‘Cached’ links):
Now try the following query to find the more interesting e-mails:
Update: Google cache no longer contains the above information.
This page contains all entries posted to Nitesh Dhanjani in November 2005. They are listed from oldest to newest.
October 2005 is the previous archive.
December 2005 is the next archive.
Many more can be found on the main index page or by looking through the archives.