Web Hack List

Collected research

Pwning Opera Unite with Inferno's Eleven

Pwning Opera Unite with Inferno’s Eleven

Eleven flaws in the Opera Unite 10 beta, tested against Build 1703. Username and computer-name enumeration, service-owner IP and port disclosure, plain-HTTP service pages, phishing hosted on trusted operaunite.com, CSRF file upload yielding stored XSS that steals the ACL password, CSRF against the Fridge and chatroom, cookie XSS via Flash header forging, and weak default passwords.

Record

Document
Pwning Opera Unite with Inferno’s Eleven
Researcher
Inferno
Published by
securethoughts.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Inferno, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .