The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Writing Secure Code: Preventing Cross-Site Scripting
Time: 11:40 EST/16:40 GMT | News Source: Microsoft | Posted By: Chad Myers

Late last year, a vulnerability was discovered in a Web page in the passport.com domain that had a very subtle flaw similar to the example above. By sending a Hotmail® recipient a specially crafted e-mail, the attacker could cause script to execute in the passport.com domain because Hotmail is in the hotmail.passport.com domain. And this means the code could access the cookies generated by the Passport service used to authenticate the client. When the attacker replays those cookies (remember, a cookie is just a header in the HTTP request), he can spoof you and access data that only you could access. Not a good thing! About three years ago, no one had heard of cross-site scripting (XSS) issues, but now I think it's safe to say we hear of at least one or two issues per day on the Web. So what's the problem and why are they serious? The problem is two-fold:

  • Trusting input from an external, untrusted entity, such as a user
  • Displaying said input as output

This is bad because a malicious user could access another's important data, such as their cookies.

Write Comment
Return to News

  Displaying 576 through 581 of 581
Prev | First
  The time now is 12:00:08 PM ET.
Any comment problems? E-mail us
#576 By 4240821 (82.115.4.230) at 7/19/2025 2:25:07 PM
https://justpaste.me/Z8bd1
https://justpaste.me/bZbg5
https://justpaste.me/Ze6I
https://justpaste.me/bvpB2
https://justpaste.me/b0dc1
https://justpaste.me/ac6M
https://justpaste.me/ZCkq3
https://justpaste.me/cLoc4
https://justpaste.me/YwDx2
https://justpaste.me/aRGP3

#577 By 4240821 (82.115.4.230) at 7/21/2025 12:03:14 AM
https://justpaste.me/dJij1
https://justpaste.me/dNqf4
https://justpaste.me/coMd2
https://justpaste.me/cfnT5
https://justpaste.me/arRV3
https://justpaste.me/ZlEn1
https://justpaste.me/Zd3t2
https://justpaste.me/aVkh1
https://justpaste.me/ZTki5
https://justpaste.me/cjga3

#578 By 4240821 (82.115.4.230) at 7/22/2025 6:53:18 PM
https://moanio.com/video.php?id=3068
https://moanio.com/video.php?id=4461
https://moanio.com/video.php?id=4251
https://moanio.com/video.php?id=2521
https://moanio.com/video.php?id=4994
https://moanio.com/video.php?id=3394
https://moanio.com/video.php?id=5363
https://moanio.com/video.php?id=2460
https://moanio.com/video.php?id=209
https://moanio.com/video.php?id=4878

#579 By 4240821 (82.115.4.230) at 7/25/2025 9:39:02 AM
https://moanio.com/video.php?id=3359
https://moanio.com/video.php?id=2194
https://moanio.com/video.php?id=4348
https://moanio.com/video.php?id=1932
https://moanio.com/video.php?id=4667
https://moanio.com/video.php?id=3211
https://moanio.com/video.php?id=4987
https://moanio.com/video.php?id=1296
https://moanio.com/video.php?id=504
https://moanio.com/video.php?id=5281

#580 By 4240821 (82.115.4.230) at 7/26/2025 5:17:12 PM
https://moanio.com/video.php?id=4560
https://moanio.com/video.php?id=419
https://moanio.com/video.php?id=2387
https://moanio.com/video.php?id=829
https://moanio.com/video.php?id=3858
https://moanio.com/video.php?id=2606
https://moanio.com/video.php?id=5159
https://moanio.com/video.php?id=6005
https://moanio.com/video.php?id=5114
https://moanio.com/video.php?id=4972

#581 By 4240821 (82.115.4.230) at 7/28/2025 9:23:10 PM
https://moanio.com/video.php?id=439
https://moanio.com/video.php?id=4725
https://moanio.com/video.php?id=3095
https://moanio.com/video.php?id=779
https://moanio.com/video.php?id=5904
https://moanio.com/video.php?id=5920
https://moanio.com/video.php?id=3578
https://moanio.com/video.php?id=4689
https://moanio.com/video.php?id=3297
https://moanio.com/video.php?id=2724

Write Comment
Return to News
  Displaying 576 through 581 of 581
Prev | First
  The time now is 12:00:08 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *