Welcome nishith123, the newest member New user?    Register    Login
http://www.packetsource.com

Categories
Attacks and Exploits
Certifications and Career
Cryptology
Detection and Prevention
Industry and Userbase
Legal and Regulatory
Network and Infrastructure
Policies and Processes
Protocols and Services
Response and Recovery
Scanning and Auditing
Servers and Systems
Software and Applications
Standards and Methods
Tools and Utilities

Popular Tags
forensics, legal, microsoft, china, vista, spam, ddos, dos, disaster recovery, patriotact

Top Members (rating)
Kelsea (1065)
Mitchell (256)
Jennifer (207)
Paperboy (0)
Melrose2703 (0)
santhoshk (0)
Bulltrader (0)
nishith123 (0)
Atony (0)

RSS Feeds
Papers
Forum Posts

A Web Developer's Guide to Cross-SiteScripting


Written by Steven Cook Source SANS Institute
0 Save | Report | Email
Added on (Edited 02/28/07)

Cross-site scripting attacks are those in which attackers inject malicious code,<br />usually client-side scripts, into web applications from outside sources. Because<br />of the number of possible injection locations and techniques, many applications<br />are vulnerable to this attack method. Scripting attacks differ from other web<br />application vulnerabilities because they attack an application’s users, not an<br />application’s infrastructure, but they can still cause a great deal of damage. This<br />paper describes how cross-site scripting works and what makes an application<br />vulnerable, along with suggestions for developers about tools for discovering<br />cross-site scripting vulnerabilities in their applications and recommended<br />practices for creating applications that are less vulnerable to the attack and more<br />resilient against successful cross-site scripting attacks.

PDF Format Read the Complete Paper



Current Tags:
None

Add Tags:

Current Rating:
0 (0 votes)

Add Rating:


Similar content:
Cross Site Scripting (XSS) FAQ, in Cross Site Scripting
Cross-Sight ScriptingVulnerabilities, in Cross Site Scripting
Detection of SQL Injection and Cross-site ScriptingAttacks, in Web Security
A Case for Forensics Tools in Cross-Domain Data Transfers, in Forensics

Post Comment
Your Name:

Title


Comment You may use Posting Codes in your message.
Security Image:
Type the letters and numbers shown. (This is to prevent automated submissions.)

Cite in Modern Language Association (MLA) Style
"A Web Developer's Guide to Cross-SiteScripting" SANS Institute, , UTC. 04 Jul 2008, 9:17 <http://www.sans.org/reading_room/whitepapers/securecode/988.php>

Cite in Chicago Style
Steven Cook, "A Web Developer's Guide to Cross-SiteScripting," http://www.sans.org/reading_room/whitepapers/securecode/988.php (accessed Jul 04, 2008 ).