The folks at the Open Web Application Security Project publish a list of the top 10 vulnerabilities. In a recent CodeBrew I provided a quick overview of them all and spent a good amount of time focusing on the most prevalent vulnerability, Cross Site Scripting (XSS).  image

I gave an overview of XSS, stepped through a quick demo (sorry vulnerable site), reviewed the three XSS variations and talked a bit about how to protect one’s site. 

References and reading materials were also included in the presentation and, look at that, they are provided here too.

  1. Open Web Application Security Project
  2. The OWASP Top Ten Vulnerabilities (pdf)
  3. OWASP List of Vulnerabilities
  4. The 56 Geeks Project by Scott Johnson
  5. ha.ckers.org
  6. OWASP XSS Prevention Cheat Sheet
  7. Wikipedia
  8. Is XSS Solvable?, Don Ankney
  9. The Anatomy of Cross Site Scripting, Gavin Zuchlinski

3 Comments to “Website Vulnerabilities”

  1. granda a gógentid si vatalha badeogrul con trado. duptaso avescu se cistas son tario mi armanalha dignambi y olitidig patin dimpe.

  2. Magnificent goods from you, man. I’ve understand your stuff previous to and you’re just too fantastic. I actually like what you have acquired here, certainly like what you are stating and the way in which you say it. You make it entertaining and you still care for to keep it wise. I cant wait to read much more from you. This is actually a tremendous website.

  3. I attempted emailing but I am not certain if it was sent, so I’ve left a comment just to say that I’ve given you a spot on the featured resource list on our internet site. Whilst a link back to our website could be great, it is not required as we think the content on your own web site is going to be beneficial to our readers any way. The link is on the front of our web site here Coral Geeks.

Leave a Reply

You can wrap your code with [ruby][/ruby] or [python][/python] blocks for syntax highlighting and you can use these traditional tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>