Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: XSS

From: Matthew Miller <mmiller(at)atstake.com>
Date: Wed Dec 11 2002 - 16:29:31 EST


Ed,

Comments inline....

On Wednesday, December 11, 2002, at 03:15 PM, Ed Tracy @ Aspect Security wrote:

>
> John,

If there is no persistent data this is true...keep in mind your application may be safe, but the components on which you host it may be vulnerable.
>
> However, if your site has any content-altering vulnerabilities (would
This is basically what I am trying to describe with persistent XSS.

> Academic detail:

Examples of transaction based cross-site scripting include, area tags, a form on another site, redirects from another site (meta tags, script), html based email, malicious applications, etc... All of the above require user action; clicking on a link, submitting a form, visiting a malicious site. opening an email, executing an application.

Examples of persistent data stores would be databases (e.g. 3 tier web app), files in which data is stored (e.g. webmail), other sites the application receives data from (e.g. newsfeeds), in memory (e.g. web-based chat server), client side data stores (e.g. cookies), etc...All of the above do not require user action, all the user has to do is visit the vulnerable site.

Do you need help?X

Just a note, but XSS does not always have to be script code....HTML injection may be a better term, but XSS seems to have caught on.

mm

>
> -Ed
>
>> Hi All,
Received on Wed Dec 11 19:45:04 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:46 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library