Sponsored White Papers, Webcasts, and Downloads
TechRepublic Resources
- Application-Level Attacks: Phishing and Session Hijacking (Level 300)
- This webcast will provide in-depth demonstrations of a variety of Web application hacking techniques such as SQL Injection and Cross Site Scripting XSS and show how to identify whether an application is vulnerable to these types of attacks. Discover how the SQL Injection hacking methodology can transfer to other areas,...
- Tags: Technique, XSS, Attack, Hacking, Phishing, Productivity, Keyboards, Security, Spam And Phishing, Hardware, Peripherals
- Webcasts
- The Anatomy of Cross Site Scripting
- Cross site scripting XSS flaws are a relatively common issue in web application security, but they are still extremely lethal. They are unique in that, rather than attacking a server directly, they use a vulnerable server as a vector to attack a client. This can lead to extreme difficulty in...
- Tags: XSS
- White papers
- MSDN Webcast: Live From TechEd: How Hackers Hack - Level 200
- Learning how hackers do what they do is a necessary to understand how to design and code defensively. This webcast looks at hacker's approaches to things like buffer overrun exploits, cross-site scripting attacks, SQL Injection, component spoofing, session hijacking, and more. Through this webcast developers will learn how hackers attack...
- Tags: Microsoft Developer Network, Buffer-overrun, Webcast, XSS, Hacker, Hacking, Digital Media, Security, Consumer Electronics, Personal Technology
- Webcasts
- Live From Redmond: How Hackers Reverse Engineer and Exploit an ASP.NET AJAX Application
- This Webcast defines how to reverse engineer and exploit an ASP.NET AJAX application. Attendees will learn how a hacker looks at the application and what information they gather from exploring the applications architecture. This webcast discusses the threat of Cross-Site Scripting XSS, what it is and how this dangerous application...
- Tags: XSS, Microsoft ASP.NET, Hacker, AJAX, Internet, Software/Web Development, Web Development, Web 2.0
- Webcasts
- Understanding Web-Based Threats and How to Thwart Them
- The Web has never been more hostile and new dangers can lurk on even the most trusted Web sites. What's more, the potential harm that cross-site scripting XSS, cross-site request forgeries CSRF, and JavaScript malware payloads can cause is growing exponentially. Intranet hacking, history stealing, browser port scanning, and dozens...
- Tags: Web, Sophos Plc., XSS, JavaScript, Malware, Intranet, Channel Management, Spyware, Adware & Malware, Security, Marketing
- Webcasts 2007-09-20
- What is cross-site scripting?
- Cross-site scripting, also known as "XSS," is a class of security exploit that has gotten a fair bit of attention in the last few years. Many users, and even Web developers, aren't entirely clear on what the term means, however. I'll explain cross-site scripting for you, so you...
- Tags: XSS, JavaScript, Web Site, Web Browser, Exploit, Cross-site Scripting Exploit, Cookies, Web Site Development, Internet, Chad Perrin
- Blog posts 2008-03-18
- TechNet Webcast: How Microsoft Online Services Defends Against Cross-Site Scripting Vulnerabilities (Level 300)
- Cross-Site Scripting XSS vulnerabilities are a serious threat to providing Microsoft Online Services customers with a trustworthy computing experience. This webcast explains how inconsistently or poorly integrated validated output can cause XSS vulnerabilities. The attendee will learn how the Microsoft Anti-Cross Site Library provides product teams with a reliable, standard...
- Tags: Webcast, XSS, Cross-site Scripting Vulnerability, Microsoft Corp., Microsoft TechNet
- Webcasts 2007-04-24
- Importance of Web Application Firewall Technology for Protecting Web-Based Resources
- Web-based applications and services have changed the landscape of information delivery and exchange in today's corporate, government, and educational arenas. Ease of access, increased availability of information, and the richness of web services have universally increased productivity and operational efficiencies. These increases have led to heavier reliance on web-based services...
- Tags: Web, CyberTrust, XSS, Web Application, Application Firewall, Channel Management, Firewalls, Identity Theft, Security, Marketing, Networking
- White papers 2008-01-10
- ISA Server 2000 Security Update for Error Pages (exe)
- A security issue has been identified in ISA Server that could allow an attacker to execute a cross-site scripting attack. You can help protect your computer by installing this update from Microsoft. This version is the first release on CNET Download.com.
- Tags: Microsoft ISA Server 2000, XSS, Microsoft ISA Server, Microsoft Corp., Security Issue, Security
- Software downloads 2007-09-14
- TechNet Webcast: How Microsoft Online Services Defends Against Cross-Site Scripting Vulnerabilities (Level 200)
- Cross-Site Scripting XSS vulnerabilities are a serious threat to providing Microsoft Online Services customers with a trustworthy computing experience. This webcast explains how inconsistently or poorly integrated validated output can cause XSS vulnerabilities. The attendee will learn how the Microsoft Anti-Cross Site Library provides product teams with a reliable, standard...
- Tags: Webcast, XSS, Cross-site Scripting Vulnerability, Microsoft Corp., Microsoft TechNet
- Webcasts 2007-04-24
- Mozilla set to secure cross-site scripting in Firefox 3
- XSS (a.k.a. cross-site scripting) attacks are a bane that accompanies the world of mashups and Web 2.0 features on the Net. However, the problem may be solved in the next major release of Mozilla's Firefox 3 with support for the new W3C draft to secure XML over HTTP. ...
- Tags: Web, Mozilla Firefox, XSS, Mozilla Corp., Arun Radhakrishnan
- Blog posts 2007-08-23
- Redundant Servlets Vulnerable to XSS Attack
- Vulnerability Description: The remote web server includes an example JSP application (/tomcat-docs/) that fails to sanitise user-supplied input before using it to generate dynamic content in an error page. An unauthenticated remote attacker may be able to leverage this issue to inject arbitrary HTML or script code into a user's...
- Tags: Application servers, Middleware, OPEN SOURCE, SECURITY, Java, mihai.balta@..., documentation web application, XSS, servlet
- Discussion threads 2007-07-20
- Redundant Servlets Vulnerable to XSS Attack (Un-deploy Tomcat documentation
- Vulnerability Description: The remote web server includes an example JSP application (/tomcat-docs/) that fails to sanitise user-supplied input before using it to generate dynamic content in an error page. An unauthenticated remote attacker may be able to leverage this issue to inject arbitrary HTML or script code into a user's...
- Tags: Application servers, Middleware, OPEN SOURCE, mihai.balta@..., servlet, Apache Tomcat, documentation web application, XSS
- Discussion threads 2007-07-20
- Use the revised OWASP Top Ten to secure your Web applications -- Part 2
- Cross site scripting XSS vulnerabilities are normally found in Web applications in which code injection is allowed. It is the most common Web application vulnerability. Scripts exploiting this weakness can cause serious problems for home and business users. In this download, Tom Olzak explores the types of cross site scripting...
- Tags: XSS, Web Application
- Download resources 2007-03-05
- Scanning Ajax for XSS Entry Points
- The continuous adoption of Web 2.0 architecture for web applications is instrumental in Ajax, Web services and Flash, emerging as key components. Ajax is a combination of technologies such as JavaScript with the XMLHttpRequest object, DOM and XML streams. Cross site scripting XSS can make browsers vulnerable to critical information...
- Tags: XSS, Entry Point, AJAX, Internet, Software/Web Development, Web Development, Web 2.0
- White papers 2007-02-15
- Cross site scripting ?
- Hmm on occasion when posting a response to a question. I'm getting block foe cross site scripting from an untrusted source.This came up on NoScripts' console.Warning: Error in parsing value for property 'CURSOR'. Declaration dropped.Source File: http://by114fd.bay114.hotmail.msn.com/cgi-bin/dasp/EN/hotmail___1000000003.cssLine: 24When the question owner has a notify on ?
- Tags: Tony Hopkinson, XSS
- Discussion threads 2007-04-20
- Protect your Web server with mod_security
- Vincent Danen tells you how to tighten up security for your Web server by implementing some simple preventive measures with mod_security. Anyone paying any attention to the number of new vulnerabilities being discovered has quickly realized that the largest "threat" to security is no longer applications bundled...
- Tags: Apache Software Foundation, Vincent Danen, Linux, OPEN SOURCE, SECURITY, Scripting languages, server, Web server, mod_security, SecFilter, Linux Tips Newsletter, TechRepublic Inc., Vulnerability, XSS, SecFilter /etc/passwdSecFilter, Web Servers, Operating Systems, Software, Internet
- Technical articles 2006-10-09
- Lock it down: Use the revised OWASP Top Ten to secure your Web applications -- Part 2
- This article is also available as a TechRepublic download.Inthis second installment in a series on the 2007 OWASP Top Ten vulnerabilities, we'lllook at the clear leader in the Web application vulnerability space -- crosssite scripting XSS. XSS vulnerabilities have been around for some time. However,the business risk associated with XSS...
- Tags: Security threats, Flaws, Web applications, attacker, vulnerability, Web application, Tom Olzak, Document Object Model, XSS
- Technical articles 2007-03-05
- Lock it down: Use the revised OWASP Top Ten to secure your Web applications -- Part 1
- This article is also available as a TechRepublic download.In Part 1 of this series I listed the OWASP Top 10 Webapplication vulnerabilities created in 2004. Shortly after that article wasposted, I received an e-mail from Andrew van derStock, OWASP executive director, giving me a heads up about the upcomingrevised list....
- Tags: OWASP Top, Security, Security threats, Tom Olzak, vulnerability, Web application, Web applications, XSS
- Technical articles 2007-02-15
- Protect your Web site from cross-site scripting attacks
- Cross-site scripting XSS attacks, a method by which attackers embed HTML scripts either in Web postings stored XSS or input fields on a Web site reflected XSS, are gaining popularity, most likely due to the relative ease with which they can be executed on unwitting victims. You can assess the...
- Tags: Web, XSS, Web Site, Attack
- Download resources 2005-06-06