★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/server_security_article-5589.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Server Security 8/28/2002 10:18

The Cross Site Scripting FAQ

Published By: Securiteam.com
Posted By: Benjamin D. Thomas
8/28/2002

Often attackers will inject JavaScript, VBScript, ActiveX, HTML, or Flash to fool a user (Read below for further details), or gather data from them. Everything from account hijacking, changing of user settings, cookie theft/poisoning, or false advertising is possible. New malicious uses are being found every day for XSS attacks. The post below by Brett Moore brings up a good point with regard to "Denial of Service", and potential "auto-attacking" of hosts if a user simply reads a post on a message board.


Click here to go to this article.
Big Fine Handed Down for Mobile Spamming
Aug 30

Remote Administration of Linux Systems
Aug 30

Data warehouses: A Security Disaster
Aug 30

Linux Advisory Watch - August 30th 2002
Aug 30

Website Security Flaw Costs ZD
Aug 29

Do Firewalls and IDS Create a False Sense of Internal Security?
Aug 29

Poll: Security Officers Fear Cyber-Attack
Aug 29

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000