contact-harvesting

1 article
sort: new top best
clear filter
0 8/10

Technical writeup demonstrating a complete XSS worm built against Atmail webmail client that bypasses HTML sanitization via quote-mixing across multiple img tags and self-propagates by harvesting contacts and sending malicious emails with CSRF tokens. The attack chains content-filtering evasion, JavaScript execution, contact extraction, and automated worm distribution.

Atmail Bishop Fox DreamHost LegalShield m:tel iiNet Optus MySpace TweetDeck
bishopfox.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details