On hamsters, Escaping, Escaping of Hamsters and the Lack of escaping in Hamster…
ID: 4e929f8c-f43d-5abc-8f49-40c12907edfc
STIX ID: report--4e929f8c-f43d-5abc-8f49-40c12907edfc
Feed Name: SensePost Blog
Threat Score
A SensePost blog post from 2007 demonstrates a proof-of-concept XSS weakness in ErrataSec's Hamster tool: by injecting encoded JavaScript into a cookie (gmailchat) and leveraging Hamster's parsing, an attacker can execute arbitrary script in the Hamster web console (including redirects and BeEF/backframe hooks) without user interaction; the post documents exploitation steps, encoding bypasses, and notes Hamster was a demo POC not intended for public use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
