All Posts Tagged XSS

Google search box opens up XSS vulnerability

November 29th, 2006 | No comments

Couldn’t think of a sarcastic title for this post, and I don’t think it makes a heck of a lot of difference anyway – it’s just news, and not much to worry about. The Google Search Appliance, that box companies throw on the rack to help them weed through data on their own networks, opens [...]

Cross-site scripting goes primetime

September 25th, 2006 | No comments

Cross-site scripting attacks are hitting major websites, including MySpace, YouTube, and even venerable oldies like MSN, Dell, and Apple. XSS attacks were long a tool of cute little script kiddies who malformed sites for the joy of their cute little friends. As a result, some still question how big the threat really is. Just when [...]

The Script Kiddie Cookbook

August 15th, 2006 | No comments

When a script kiddie injects a chunk of javascript or a frame into a website, it generally gets fixed pretty quickly and everyone laughs about it. Maybe developers should think twice – those XSS exploits can cause a lot of harm, as detailed here. I just got though jumping through hoops, getting special characters stripped [...]