What is Cross Site Scripting?
when a web application gathers malicious data from a user.
If for example I was logged in as "john" and read a message by "joe" that contained malicious javascript in it, then it may be possible for "joe" to hijack my session just by reading his bulletin board post.
What are the threats of Cross Site Scripting?
Often attackers will inject JavaScript, VBScript, ActiveX, HTML, or Flash into a vulnerable application to fool a user (Read below for further details) in order to gather data from them.
No more explanation, it is enough with cross site scripting...i'm bored with
CSS vuln ;)
http://www.phpnuke.org/user.php?op=userinfo&uname=
What can I do to protect myself as a vendor?
Never trust user input and always filter metacharacters. This will eliminate the majority of XSS attacks. Converting < and > to < and > is also suggested when it comes to script output. ...URL ENCODE
http://docs.google.com/viewer?a=v&q=cache%3AoIngv17_LjoJ%3Awww.securitydocs.com%2Fpdf%2F3261.PDF+XSS+holes&hl=en&gl=us&sig=AHIEtbSgMZAYvHGxJVZ-eG5nRo539cvXpA&pli=1
No comments:
Post a Comment