Security

Vuln Report

Since around 2006, I have been reporting vulnerabilities (mostly XSS) found in Japanese web services to the companies involved and to IPA (Information-technology Promotion Agency, Japan). Everything listed here was confirmed fixed before publication (except one case where the operator could not be reached). Rather than disclosing vulnerabilities publicly, I reported them directly; early on I once published one on my blog without contacting the operator, but after that I switched to responsible disclosure through IPA.

"What kind of threat do you believe XSS could cause?"

At the time, the dangers of XSS were not yet widely understood. This is the question that came back from the IPA Security Center after receiving my report (2006, sic, translated):

5) Threats that could arise from the vulnerability XSS

Your report contained the entry above. What kind of threat do you believe could arise from cross-site scripting? We would appreciate it if you could provide specific details.

Session hijacking via cookie theft, phishing for personal information with input forms disguised as the legitimate site — I explained such threats one by one as the report moved forward.

I also reported an XSS in goo's search, but I have lost the primary materials from that time and cannot reconstruct the details, so it is not included in the table below.

Reports

TargetRouteLocationOutcomeWindowWhen
key.blogdns.netIPA#52164334Input formClosed (operator unreachable)~3 months2006-08
nun.nuBlog postRedirectorFixed2006-09
VectorIPA#85254681info.htmlFixed~1 month2006-09
ライブドアIPA#96290952SearchFixed~1 month2006-09
u.dan.co.jpBlog postRedirectorFixed2006-11
CNET JapanDirectSearchFixed2 days2007-02
ニコニコ動画Direct + IPA#77094233SearchFixed3 days2007-02
ライブドアIPA#53681582SearchFixed~3 weeks2007-02
Buzzurl 動画検索DirectVideo searchFixedNext day2007-02
はてな検索DirectRelated-term suggestionsFixed2007-02
Apache mod_cachePublic gistHTTP cacheFixed upstream2014-06