Beefy Boxes and Bandwidth Generously Provided by pair Networks
Keep It Simple, Stupid
 
PerlMonks  

Re: OT: Cross-site Scripting - Articles and Tools

by cjf (Parson)
on May 13, 2002 at 11:20 UTC ( [id://166149]=note: print w/replies, xml ) Need Help??


in reply to OT: Cross-site Scripting - Articles and Tools

Usually when people talk about cross-site scripting attacks they refer to someone posting malicious code to a website in hopes of exploiting the browser vulnerabilities of other visitors.

What's often overlooked is using the visitor to submit bad information to a vulnerable script on (or off) the site. This is easily done through adding a link with some extras attached to the query string, or adding a form with a few extra parameters. Maybe those buttons you click on people's homenodes could be sending less than nice stuff to certain scripts?

Of course, if everyone was adequately paranoid and Didn't trust user input, this wouldn't be as big of a problem as it is.

  • Comment on Re: OT: Cross-site Scripting - Articles and Tools

Log In?
Username:
Password:

What's my password?
Create A New User
Domain Nodelet?
Node Status?
node history
Node Type: note [id://166149]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this?Last hourOther CB clients
Other Users?
Others meditating upon the Monastery: (7)
As of 2024-04-25 08:19 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    No recent polls found