Cатсн²² (in)sесuяitу / ChrisJohnRiley

Because we're damned if we do, and we're damned if we don't!

Tag Archives: xss

DEEPSEC: Ground BeEF: Cutting, devouring and digesting the legs off a browser

Ground BeEF: Cutting, devouring and digesting the legs off a browser Michele Orru So who thinks XSS attacks are lame? Real-Life XSS Pwning : 2005: Samy Worm 2006: Yamanner worm 2008 XSS in Obama Website 2010: Apache pwned through XSS in Jira 2010: Stored XSS in YouTube 2011: Multiple XSS on Google,com What is BeEF [...]

Blackhat Europe: Universal XSS via IE8′s XSS Filters

Universal XSS via IE8′s XSS Filters (David Lindsay & Eduardo Vela Nava) Abstract (source: Blackhat.com) Internet Explorer 8 has built in cross-site scripting (XSS) detection and prevention filters. We will explore the details of how the filters detect attacks, the neutering method, and discuss the filters’ general strengths and weaknesses. We will demonstrate several ways [...]

alert(‘xss’) – The slow death of XSS

Ever since I took my first baby steps in web application penetration testing, I’ve seen people using alert(‘xss’) and alert(document.cookie) to prove an application is vulnerable to cross-site scripting. Despite the title of this little rant (and yes, it is a rant), I’ve got no problem with that… up to a point. We need something [...]

TYPO3 Advisories (TYPO3-SA-2009-016)

Some people may have noticed the addition of an “advisories” section to the blog over the last few days. Despite the fact I’m drugged up on painkillers and muscle relaxants, I managed to post up some information about the newest TYPO3 Security Advisories released in the past week. Although the latest additions are basic XSS [...]

Follow

Get every new post delivered to your Inbox.