Contributors

Jeremiah Grossman
(WhiteHat Security)

Ofer Shezaf
(Breach Security ) [Project Leader]

The Web Hacking Incidents Database
Last update:07 November 2007

List of incidents of class Content Spoofing

Other WASC threat classifications:
Abuse of Functionality, Brute Force, Content Spoofing, Credential/Session Prediction, Cross-site Scripting, Defacement, Denial of Service, Directory Indexing, HTTP Response Splitting, Information Leakage, Insufficient Anti-automation, Insufficient Authentication, Insufficient Authorization, Insufficient Process Validation, Insufficient Session Expiration, Known Vulnerabity, Misconfiguration, OS Commanding, Other, Path Traversal, Phishing, Predictable Resource Location, Redirection, SQL Injection, Unknown, Weak Password Recovery Validation, Worm


There are 4 incidents of class Content Spoofing
WHID 2006-45: Man arrested for hacking Internet shopping malls
Date: 17 December 2006
Incident Type: Security Breach
WASC Threat Classification: Content Spoofing

A Korean shopping system was vulnerable to hidden field manipulation and a determined hacker purchased $6000 worth of merchandize at 45 stores for much less.

References:

WHID 2005-8: eBay Redirect Becomes Phishing Tool
Date: 03 March 2005
Incident Type: Security Breach
WASC Threat Classification: Content Spoofing, Cross-site Scripting

References:

WHID 2004-13: SunTrust site XSS vulnerability exploited by for phishing
Date: 06 December 2004
Incident Type: Security Breach
WASC Threat Classification: Content Spoofing, Cross-site Scripting

Phishing based on XSS (Same vulnerability but a different attack that the similar September 2004 attack)

References:

WHID 2004-11: Phishers Manipulate SunTrust Site to Steal Data
Date: 28 September 2004
Incident Type: Security Breach
WASC Threat Classification: Content Spoofing, Cross-site Scripting

Phishing based on XSS

References:




This work is licensed under the Creative Commons Attribution License. To view a copy of this license, visit http://creativecommons.org/licenses/by/2.5/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

© Copyright 2005, Web Application Security Consortium. All rights reserved.