Blog: Reducing XSS by way of Automatic Context-Aware Escaping in Template Systems

Written by Jad S. Boutros, Google Security Team

Wednesday, 2 June 2010

An interesting blog post by Google's Online Security Team, ntroducing Automatic Context-Aware Escaping (Auto-Escape for short), a functionality the team added to two Google-developed general purpose template systems to better protect against Cross-Site Scripting (XSS).


read more...

Browser Hijacking Techniques 2009

Written by p3lo

Sunday, 3 May 2009

An interesting paper by p3lo concerning the new XSS vectors, javascript malware obfuscation , url cache poisoning, packing, frame jacking techniques etc..  


read more...

WordPress.com permanent XSS vulnerability

Written by Pedro Laguna

Thursday, 16 April 2009

An interesting article about an xss vulnerability in a theme that was installed on wordpress.com.


read more...

How to write a XSS (cross site scripting) worm for McCodes sites

Written by PaPPy

Monday, 19 January 2009

How to write a XSS (cross site scripting) worm for McCodes sites


read more...

Open redirect vulnerabilities: definition and prevention

Written by Russ McRee, HolisticInfoSec.org

Sunday, 6 July 2008

(IN)SECURE Magazine Issue 17, includes Russ's article about open redirect vulnerabilities. Covers them in detail by providing info on real-world examples, prevention solutions and the relation with PCI-DSS standards.


read more...

Paper: Smashing the Web for fun & profit using XSS

Written by Gerasimos Kassaras, blog.kassaras.com

Monday, 23 June 2008

In this tutorial paper, Gerasimos describes in full detail how to perform  an XSS filter invasion and run his JavaScript key logger in order to steal user names, passwords and user credentials.


read more...

2 3 4 5 

 

38463 total xss
12438 special xss
2224 fixed
5600 xss onhold
1760 EW subscribers

Home | News | Articles | Advisories | Submit | Alerts | Links | What is XSS | About | Contact | Some Rights Reserved.