The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Writing Secure Code: Preventing Cross-Site Scripting
Time: 11:40 EST/16:40 GMT | News Source: Microsoft | Posted By: Chad Myers

Late last year, a vulnerability was discovered in a Web page in the passport.com domain that had a very subtle flaw similar to the example above. By sending a Hotmail® recipient a specially crafted e-mail, the attacker could cause script to execute in the passport.com domain because Hotmail is in the hotmail.passport.com domain. And this means the code could access the cookies generated by the Passport service used to authenticate the client. When the attacker replays those cookies (remember, a cookie is just a header in the HTTP request), he can spoof you and access data that only you could access. Not a good thing! About three years ago, no one had heard of cross-site scripting (XSS) issues, but now I think it's safe to say we hear of at least one or two issues per day on the Web. So what's the problem and why are they serious? The problem is two-fold:

  • Trusting input from an external, untrusted entity, such as a user
  • Displaying said input as output

This is bad because a malicious user could access another's important data, such as their cookies.

Write Comment
Return to News

  Displaying 601 through 609 of 609
Prev | First
  The time now is 10:06:01 PM ET.
Any comment problems? E-mail us
#601 By 4240821 (178.217.45.24) at 8/11/2025 5:23:00 AM
https://www.xfree.com/schalossieta249
https://www.xfree.com/gandetubi289
https://www.xfree.com/stossuticde875
https://www.xfree.com/unagflapil108
https://www.xfree.com/winsdosgeouhap308
https://www.xfree.com/tiamoniberc991
https://www.xfree.com/hecepleno423
https://www.xfree.com/granenkonwhoe63
https://www.xfree.com/afumssiger462
https://www.xfree.com/inprefungloc901

#602 By 4240821 (82.115.4.230) at 8/11/2025 7:02:33 PM
https://www.xfree.com/magertimo639
https://www.xfree.com/hindnewima677
https://www.xfree.com/neytranranre769
https://www.xfree.com/contdolzadup636
https://www.xfree.com/trenacatlua570
https://www.xfree.com/siopretceming616
https://www.xfree.com/racomgyomaxf638
https://www.xfree.com/moscilove725
https://www.xfree.com/ooktocardao662
https://www.xfree.com/thioujacowork675

#603 By 4240821 (82.115.4.230) at 8/12/2025 11:32:41 AM
https://www.xfree.com/zabiturnhar912
https://www.xfree.com/danketsgrasel192
https://www.xfree.com/raihodlosam942
https://www.xfree.com/etosgomis752
https://www.xfree.com/ndunmatipcio338
https://www.xfree.com/digtidopi342
https://www.xfree.com/amsupvexy171
https://www.xfree.com/hieblunrigja990
https://www.xfree.com/concocede522
https://www.xfree.com/panrattcoter681

#604 By 4240821 (82.115.4.230) at 8/13/2025 4:12:35 AM
https://www.xfree.com/tranaferwa72
https://www.xfree.com/credmogasan974
https://www.xfree.com/enreraraph59
https://www.xfree.com/rodsolawbtrem371
https://www.xfree.com/conssoftspinen819
https://www.xfree.com/semigzole266
https://www.xfree.com/farraulinduns496
https://www.xfree.com/stapozhimpuu318
https://www.xfree.com/disttikaso643
https://www.xfree.com/gaitiecige343

#605 By 4240821 (82.115.4.230) at 8/14/2025 6:06:39 AM
https://www.xfree.com/warecvechic760
https://www.xfree.com/utscanemgam356
https://www.xfree.com/osounlibug37
https://www.xfree.com/mandeaconke747
https://www.xfree.com/propsuquarli499
https://www.xfree.com/brahgawecte518
https://www.xfree.com/tinmikarta913
https://www.xfree.com/gemerbaithy425
https://www.xfree.com/nestparnabi758
https://www.xfree.com/lassnessadump637

#606 By 4240821 (82.115.4.230) at 8/14/2025 4:54:41 PM
https://www.xfree.com/buyviaglarom126
https://www.xfree.com/lacdemartho374
https://www.xfree.com/macgenotu405
https://www.xfree.com/medevathu844
https://www.xfree.com/biomermaven885
https://www.xfree.com/bafdowbbestvi127
https://www.xfree.com/sonhokefe169
https://www.xfree.com/pazcmanflota973
https://www.xfree.com/prescosszelmy425
https://www.xfree.com/kpotabterti541

#607 By 4240821 (82.115.4.230) at 8/15/2025 4:12:06 PM
https://www.xfree.com/verjohnnusna176
https://www.xfree.com/tiwsinesga642
https://www.xfree.com/gungepavvi554
https://www.xfree.com/reiclinectwen969
https://www.xfree.com/concaturli761
https://www.xfree.com/thioujacowork675
https://www.xfree.com/newlicarfarm348
https://www.xfree.com/schemitcomme499
https://www.xfree.com/ecdwelkirscon72
https://www.xfree.com/cirityma633

#608 By 4240821 (82.115.4.230) at 8/16/2025 2:48:42 PM
https://www.xfree.com/juskacibo510
https://www.xfree.com/naiseevercall225
https://www.xfree.com/femcchomara319
https://www.xfree.com/tiodethekro260
https://www.xfree.com/faitracgasme190
https://www.xfree.com/marciromwo562
https://www.xfree.com/berstontiogreg860
https://www.xfree.com/camptegolfrin706
https://www.xfree.com/healthreszhengsi42
https://www.xfree.com/platesinge615

#609 By 4240821 (82.115.4.230) at 8/16/2025 9:27:07 PM
https://www.xfree.com/schemitcomme499
https://www.xfree.com/ptoswebsritsge985
https://www.xfree.com/inupamiph562
https://www.xfree.com/onefunnur814
https://www.xfree.com/riamaxfero372
https://www.xfree.com/riacixaba653
https://www.xfree.com/spokehinne520
https://www.xfree.com/newlicarfarm348
https://www.xfree.com/prescosszelmy425
https://www.xfree.com/rateltieter549

Write Comment
Return to News
  Displaying 601 through 609 of 609
Prev | First
  The time now is 10:06:01 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *