Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What does XSS have to do with remote code execution? I mean, it's possible for a Javascript parser to have vulnerabilities that can lead to arbitrary code execution, but the Amazon example seems in no way relevant here.


Well, it's a Register article. I left open the possibility that they called "remote script execution" remote code execution. They already said it gains root access, but then later said it gives shell access, which is not the same thing (since skype does not run as root).

I have no idea what the bug is, all I meant was that it wasn't completely out of the realm of possibility to have something render a payload.


Fair enough. The article does link to the actual blog post though (http://www.purehacking.com/blogs/gordon-maddern/skype-0day-v...).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: