Search / 51 posts tagged cross-site

Subscribe
  1. Photo of narres

    Prominent Web sites have serious coding flaw

    http://newsclick.biz/ node/ 128368

    Two Princeton University academics have found a type of coding flaw on several prominent Web sites that could jeopardize personal data and in one alarming case, drain a bank account.The type of flaw, called cross-site request forgery (CSRF), allows an attacker to perform actions on a Web site on

  2. Photo of rmcree

    XSF & XSS: Double your pleasure, double your fun

    http://holisticinfosec.blogspot.com/ 2008/ 09/ xsf-xss-double-your-pleasure-doub…

    If you've read this blog, or those of my peers, you're likely quite familiar with cross-site scripting, and the problems associated with open redirect vulnerabilities. A vulnerability you may be less familiar with is cross-site framing, which largely couples the best of both above-mentioned vulnerabilities.

  3. View all »

    Videos about cross-site

    1. Cross site scripting i "Linuks już nie darmowy"
    2. Cross Site Scripting (Basic Hacking 1)
    3. TubeMogul Tutorial: Cross-Site Analytics
    4. MasOportunidades cross-site scripting - hacking phishing ps3
  4. No one has claimed this blog

    Top Five Web Application Vulnerabilities 9/2/08 - 9/14/08

    http://www.communities.hp.com/ securitysoftware/ blogs/ top5/ archive/ 2008/ 09/…

    1) Joomla! Multiple Remote Vulnerabilities and Weaknesses Joomla! is susceptible to multiple remote vulnerabilities which are exploitable via a browser. Remote attackers can leverage these issues to conduct phishing attacks, redirect victims to attacker-controlled sites, and send unsolicited spam.

  5. Photo of glyphobet

    HttpOnly cookies in Python & Pylons

    http://glyphobet.net/ blog/ blurb/ 285

    Thanks to Jeff Atwood for posting about the benefits of the HttpOnly flag on cookies. Support for HttpOnly cookies has now been added to Python 2.6’s Cookie module, and Paste’s WSGIResponse. Pylons applications can now use the HttpOnly flag to protect cookies, significantly raising the bar against XSS attacks on users of those applications.

  6. No one has claimed this blog

    Devollo.com: Data Filtering Using PHP's Filter Functions - Part ...

    http://computer-internet.marc8.com/ devollo-com-data-filtering-using-phps-filter…

    On Devollo.com the first part of a series looking at something every PHP developer (or any other for that matter) should include in their application - data filtering. read more

  7. Photo of ShaolinTiger

    CSRF Vulnerability in Twitter Allows Forced Following

    http://www.darknet.org.uk/ 2008/ 09/ csrf-vulnerability-in-twitter-allows-forced…

    I did mention this earlier in the week when I was talking about Twitter being used as a malware distribution platform, there also seems to be an auto follow vulnerability that spammers would love. Do you remember Myspace and samy with 900,000 friends?

  8. No one has claimed this blog

    Ultimate Attack Vectors - Web Browsers

    http://preachsecurity.blogspot.com/ 2008/ 09/ ultimate-attack-vectors-web-browse…

    Talking about web application security lately is making me nuts. It's been about what, 12 years since we security folks started preaching about "firewalls", right? That took at least 5 years before anyone started taking firewalls with any serious thought - and now it's just a matter of need when building a network.

  9. No one has claimed this blog

    [2/5] Sun Java System Portal Server Cross-Site Scripting Vulnera...

    http://motd.ambians.com/ news/ 2-5-sun-java-system-portal-server-cross-site-scri…

    Description : A vulnerability has been reported in Sun Java System Portal Server, which can be exploited by malicious people to conduct cross-site scripting attacks.

  10. Photo of simonwhatley

    How to Fix a SQL Injection Attack

    http://www.simonwhatley.co.uk/ how-to-fix-a-sql-injection-attack

    In my previous post, What is a SQL Injection Attack, I gave a brief overview of SQL injection and Cross-Site Scripting (XSS), primarily with regard to websites. In the example given, we saw that an attack could take the form of a ‘hacked’ URL which contained either a literal SQL statement, or a hexadecimal string that could be interpreted by an insecure SQL database server.

  11. Photo of simonwhatley

    What is a SQL Injection Attack

    http://www.simonwhatley.co.uk/ what-is-a-sql-injection-attack

    Over the past few weeks, subversive elements in the international arena have decided that attacking websites is a fun thing to do! The online world has become the new battle ground between nations vying to de-stabilise rivals.

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6

Rising and falling

Technorati data powered by Truviso

Mentions by Day

Posts tagged cross-site per day for the past 30 days.

Chart of results for cross-site

See your posts here

To contribute to this page, include this code in your blog post: