Domain: cgisecurity.com
Stories and comments across the archive that link to cgisecurity.com.
Comments · 196
-
Sort of, but not quite
The exploit uses the concept of cross-site scripting (XSS, not CSS). XSS can work in some interesting ways to trick users. It's certainly more sophisticated than your typical "www.somerandomsite.com/ebay/login.cgi" phishing schemes you see.
You can read some more about XSS. -
The Cross Site Scripting FAQ
-
This is Cross Site Scripting
-
Additional AJAX Security Resources
-
The Cross Site Scripting FAQ
-
This is Cross Site Scripting
I've written an FAQ on this type of attack which can be found below.
The Cross Site Scripting FAQ -
Web Vulnerability Links
-
Web Vulnerability Links
-
MySQL Security
-
Not linked off of amazon.com, possible phishing?
This isn't linked off of www.amazon.com this could be a phishing scam......
- webappsec
Web Security -
Ajax Security
-
The Cross Site Scripting FAQ
-
For further reading
Since I know only about 12 programming languages and use maybe 10 libraries between them all, that makes me next to computer illiterate these days. So I didn't know what XSS was, but found this site: http://www.cgisecurity.com/articles/xss-faq.shtml extremely informative. Including some HEX code that looks like fun!
-
AJAX Security
-
Incorrect title
The problem is with the proxy servers, not IE.
Read the paper
Yawn... -
Advisory URL
-
AJAX Security
-
MirrorMask Show in Atlanta
Atlanta has a showing of mirrormask for 1 week only. The artist of mirrormask also does the sandman covers.
Movie Times: http://www.atlantamovietimes.com/movies/4798910.ph p?date=0
- z
http://www.cgisecurity.com/ -
AJAX Security
-
Oh god, not again...
When WPF/E becomes available, it will be in the form of an Active X control that can be embedded in applications or as browser plug-in.
*pictures Bill Gates screaming "lalalala!" when presented with report like these* -
The Cross Site Scripting FAQ
-
Anatomy of the Web Application Worm
For those wondering about other advances/predictions in worms check out this paper I wrote a few years ago.
http://www.cgisecurity.com/articles/worms.shtml -
Web Attack Security Documentation
-
Web Security RSS Feed
-
Speaking of google bombing
Bomb this Web Security news
-
Web Application Security Links
-
Web Application Security Links
-
Web Application Security Links
-
Web Application Security Links
-
What is SQL Injection?
-
Cross Site Scripting FAQ
-
Web Security Pen Testing resources
-
Web Security Pen Testing resources
-
Web Security Pen Testing resources
-
.NET Security resources
-
Web Security news RSS feed
-
Fingerprinting Port 80 Attacks: Attack Forensics
Here are the links to two papers describing forensic log analysis of web based attacks. Worth a look.
Fingerprinting Port80 Attacks Part 1
Fingerprinting Port80 Attacks Part 2 -
Fingerprinting Port 80 Attacks: Attack Forensics
Here are the links to two papers describing forensic log analysis of web based attacks. Worth a look.
Fingerprinting Port80 Attacks Part 1
Fingerprinting Port80 Attacks Part 2 -
Cross Site Scripting FAQ: Questions and Answers
-
Anatomy of the web application worm
Frankly I'm surprised it took this long. Here is an article I wrote about web application worms that was published 2 years ago. http://www.cgisecurity.com/articles/worms.shtml
-
Cross Site Scripting FAQ questions and answers
-
PSA: XSS cookie theft
Never heard of XSS until now (like me)? Here is one summary one summary of what the cookie theft looks like.
-
Apache Security Documentation
-
Apache security documentation
-
Apache security documentation
-
Apache security documentation
-
XSS
Three words: Cross Site Scripting
-
Re:Stupid Guy Asks...
I'll bite:
What is Cross Site Scripting" -
Secure coding documentation
-
Secure coding documentation