xss articles, videos, photos and opinions

Sort by Relevance | Date | Popularity

Facebook flooded with porn spam

...ZDNet.com on Monday suggested the attacks were due to a "self-XSS [cross-site scripting] vulnerability in the browser". Protecting the people who use... Read more

16 November, 2011 by David Meyer

Facebook locked in 'arms race' with spammers

...announced the new security features, they were calibrated for all the self-XSS attacks we'd seen at the time." The company began turning on... Read more

17 May, 2011 by Elinor Mills

Twitter patches JavaScript hack

...company's status feed identified the hack as a cross-site scripting (XSS) attack, and said Twitter had fully patched the hack on Tuesday afternoon... Read more

21 September, 2010 by Tom Espiner
Detecting <endeca_term>XSS</endeca_term> Scripting (Cross-Site Scripting

Detecting XSS Scripting (Cross-Site Scripting

...should be viewed following the Script Injection video demonstration. Cross-site scripting ('XSS' or 'CSS') is an attack that takes advantage of a Web site... Read more

1 January, 2011
Yukti: A Dynamic Agent Based IDS With Suspect Engine to Detect Diverse <endeca_term>XSS</endeca_term> Attacks

Yukti: A Dynamic Agent Based IDS With Suspect Engine to Detect Diverse XSS Attacks

...are not validated) in the client side is called CROSS Site Scripting (XSS) attack. It is called XSS because the script that is executed here... Read more

22 December, 2011
An Empirical Analysis of <endeca_term>XSS</endeca_term> Sanitization in Web Application Frameworks

An Empirical Analysis of XSS Sanitization in Web Application Frameworks

...predominant mechanism in today's applications to defend against cross-site scripting (XSS) attacks. XSS sanitization can be difficult to get right as it ties... Read more

9 February, 2011
Understanding Script Injection

Understanding Script Injection

This webcast should be viewed as a prerequisite to the XSS video demonstration. Script Injection is a form of Web application attack where... Read more

1 January, 2011
Detect and Sanitise Encoded Cross-Site Scripting and SQL Injection Attack Strings Using a Hash Map

Detect and Sanitise Encoded Cross-Site Scripting and SQL Injection Attack Strings Using a Hash Map

CROSS-Site Scripting (XSS) and SQL injection are the top vulnerabilities found in web applications. Attacks... Read more

10 December, 2010
N-Stalker Web Application Security Scanner 2012

N-Stalker Web Application Security Scanner 2012

...patent-pending self-owned technology allows to scan Web applications against SQL XSS injection, buffer overflow, parameter tampering and much more. Component-oriented Web Security... Read more

28 July, 2011

Twitter integrates Firefox 4 security feature

...called Content Security Policy (CSP) which aims to stop cross-site-scripting (XSS) attacks when they execute on the browser. Twitter has implemented CSP on... Read more

24 March, 2011

Google fixes Android Market bug

...works universally across all Android devices, versions, and architectures." Oberheide described the XSS vulnerability as "low-hanging fruit" and said he was surprised no one... Read more

8 March, 2011 by Elinor Mills

Microsoft offers security to Azure developers

...Cloud developers must concern themselves with a plethora of vulnerabilities — SQL injection, XSS, etc — that impact their applications, regardless of how they will be deployed... Read more

15 June, 2010 by Richard Thurston
ThreatSentry IIS Web Application Firewall (32-bit) 4.1.6

ThreatSentry IIS Web Application Firewall (32-bit) 4.1.6

...SQL) Injection, DoS, Cross Site Request Forgery (CSRF/XSRF), Cross-Site Scripting (XSS) and other attack techniques. ThreatSentry's conventional defense capabilities are augmented by... Read more

18 May, 2012
ThreatSentry IIS Web Application Firewall (64-bit) 4.1.6

ThreatSentry IIS Web Application Firewall (64-bit) 4.1.6

...SQL) Injection, DoS, Cross Site Request Forgery (CSRF/XSRF), Cross-Site Scripting (XSS) and other attack techniques. ThreatSentry's conventional defense capabilities are augmented by... Read more

18 May, 2012
Hackers Home 1.01

Hackers Home 1.01

...Registration Forums, Finding Spoofed Website, Block and unblock Sites, Cross site scripting (XSS), Password Cracking Tools, View Blocked Websites, Acunetix Web Vulnerability and Much more... Read more

7 May, 2012

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Jack Schofield

Moonlight wasn't a Microsoft product, so it's not really a failure for Microsoft, more a failure for open source. Or, specifically, for Novell,...

54 minutes ago by Jack Schofield on The future of .NET (Mono) on non-Windows platforms
J.A. Watson

@apexwm - You are basically right. GIMP is not included in the Fedora 17 base distribution, but it can be installed from the Add/Remove Software...

1 hour ago by J.A. Watson on Fedora 17 - The "Beefy Miracle" Arrives
Moley

@pjc158 Unfortunately our government signed away any such possibility in a entirely unequal treaty with the USA, purportedly in response to...

1 hour ago by Moley on Judge orders US to share MegaUpload evidence
J.A. Watson

@Thomas - Thanks for the tip, based on what you said I went back and downloaded the KDE spin, and installed that one another netbook (NF310). You...

1 hour ago by J.A. Watson on Fedora 17 - The "Beefy Miracle" Arrives
apexwm

JW, Thanks as always for the great review on these new releases. One thing that I've also read is that Fedora 17 will include GIMP 2.8 which is...

2 hours ago by apexwm on Fedora 17 - The "Beefy Miracle" Arrives
SoapyTablet

'Cut Price' Data Roaming? The price has been cut, but it is certainly not 'cut price' in the sense of the phrase, and nowhere near local EU data...

4 hours ago by SoapyTablet on Cut-price data roaming gets all-clear for July
apexwm

BrownieBoy: "Such crashes are normally down to the OS and/or a rogue application, which could be fixed by re-imaging. Everybody knows how Windows...

5 hours ago by apexwm on Using Windows XP is a waste of money, says IDC
Thomas Gellhaus

I've just started using it too, and like you I feel that Fedora is a fine GNOME 3 showcase distribution. I am torn, though, because I checked out...

5 hours ago by Thomas Gellhaus via Facebook on Fedora 17 - The "Beefy Miracle" Arrives
pjc158

Why is it that Newzealand has the guts to stand up to the USA and ask to see the evidence and we don't!

5 hours ago by pjc158 on Judge orders US to share MegaUpload evidence
Dean Talboys

What a farce! Hopefully the European court will see where this is leading.

7 hours ago by Dean Talboys via Facebook on Assange loses extradition battle in Supreme Court
SoapyTablet

Wouldn't surprise me if Samsung actually really had problems producing the white model (as Apple did - it would make more sense) and this non-story...

8 hours ago by SoapyTablet on Samsung Galaxy 'S3' delayed by special paint
Lonnie

those conformation letters are hard to figure out what is which letters it is a pain in the back side. Please make it more Ledge-able being better...

11 hours ago by Lonnie on Screenshots: Photoshop CS6 Beta
BrownieBoy

"cites" even. Ouch!

18 hours ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
Horace Ontalhold

...... and PDP11s too

19 hours ago by Horace Ontalhold on Fusion-io lays minefield with a billion IOPS
BrownieBoy

I had a quick skim through the PDF. It seems to be that many of these so-called cost savings would be down to a hardware refresh. Although...

20 hours ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
bobandroid

496,999 BT Fon Hotspots lovingly situated in your next door neighbours garden, no matter how you dress that up its still a pup... Not where I need...

22 hours ago by bobandroid on London Olympics: BT needs 25,000 more Wi-Fi hotspots
apexwm

Jack : I was hoping you could provide us a summary since you are familiar with this report. I am not yet sure how much of my time I'd like to...

23 hours ago by apexwm on Using Windows XP is a waste of money, says IDC
Smilig Eddie

2 – 4 more weeks of waiting: how many buyers are going to decide instead to see what the iPhone 5 offers? Consumer trust in the brand has also...

24 hours ago by Smilig Eddie on Samsung Galaxy 'S3' delayed by special paint
SRist

So it looks like this was a complete red herring - Adobe are allowing upgrades from Photoshop CS3, CS4 and CS5 at the same price. When did this...

1 day ago by SRist on Photoshop users attack Adobe upgrade policy change
Jack Schofield

@apexwm Have you considered either (a) reading the story above or (b) reading the PDF? There are answers in both.

1 day ago by Jack Schofield on Using Windows XP is a waste of money, says IDC