EXPLOIT ALERT Reddit Attacked By Javascript Comment Bomb
Reddit fans beware: a very effective XSS (cross site scripting) attack is currently live on the site: even hovering over a comment will cause all your previous Reddit comments to be replaced by a rogue message. Turning off javascript before visiting may prevent the attack, or you may simply wish to avoid Reddit until the attack is brought under control.The attacker appears to have figured out how to insert javascript into Reddit comments: thus, hovering over such a comment is all it takes to execute the javascript on your machine and replace all your comments with the rogue message. We’ve not aware of anything being downloaded to your machine at this point: only a XSS attack that essentially removes all your Reddit comments.At the time of writing, Reddit is offline.



Loading...