Security

Vuln Report

Since around 2006, I have been reporting vulnerabilities (mostly XSS) found in Japanese web services to the companies involved and to IPA (Information-technology Promotion Agency, Japan). Everything listed here was confirmed fixed before publication (except one case where the operator could not be reached). Rather than disclosing vulnerabilities publicly, I reported them directly; early on I once published one on my blog without contacting the operator, but after that I switched to responsible disclosure through IPA.

“What kind of threat do you believe XSS could cause?”

At the time, the dangers of XSS were not yet widely understood. This is the question that came back from the IPA Security Center after receiving my report (2006, sic, translated):

5) Threats that could arise from the vulnerability XSS

Your report contained the entry above. What kind of threat do you believe could arise from cross-site scripting? We would appreciate it if you could provide specific details.

Session hijacking via cookie theft, phishing for personal information with input forms disguised as the legitimate site — I explained such threats one by one as the report moved forward.

I also reported an XSS in goo’s search, but I have lost the primary materials from that time and cannot reconstruct the details, so it is not included in the table below.

Reports

TargetRouteLocationOutcomeWindowWhen
key.blogdns.netIPA#52164334入力フォーム取扱い終了(運営者不通)約3ヶ月2006-08
nun.nuブログ公開リダイレクタ修正済み2006-09
VectorIPA#85254681info.html修正済み約1ヶ月2006-09
ライブドアIPA#96290952検索修正済み約1ヶ月2006-09
u.dan.co.jpブログ公開リダイレクタ修正済み2006-11
CNET Japan直接検索修正済み2日2007-02
ニコニコ動画直接 + IPA#77094233検索修正済み3日2007-02
ライブドアIPA#53681582検索修正済み約3週間2007-02
Buzzurl 動画検索直接動画検索修正済み翌日2007-02
はてな検索直接類似語推薦修正済み2007-02
Apache mod_cache公開(gist)HTTP キャッシュ上流で修正済み2014-06