The 2008 Pwnie Nominee For Mass 0wnage

XSS of the entire web for users of Earthlink, Comcast and Verizon

Discovered by: Dan Kaminsky

Dan Kaminsky discovered that many ISPs that hijack non-existent domains to serve ads are vulnerable to cross-site scripting attacks, allowing an attacker to compromise any website on the Internet. Dan gets bonus points for using a Rickroll to demonstrate the bug.