Anti-Anti-XSS: bypassing browser defenses - OWASP Foundation

Anti-Anti-XSS: bypassing browser defenses

SMAU E-Academy Milan, 20th Oct 2007

Alberto Revelli

Portcullis Computer Security

ayr@portcullis- r00t@

Copyright ? 2007 - The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License.

The OWASP Foundation



...ABOUT ME...

Senior Consultant for Portcullis Computer Security Technical Director of Italian Chapter of OWASP (Open Web

Application Security Project) Co-author of the OWASP Testing Guide 2.0 Developer of sqlninja -

SMAU E-Academy ? Milan, 20th Oct 2007

OWASP Italy

AGENDA

Context Attacking httpOnly cookies Attacking the Same Origin Policy JS-less malware

SMAU E-Academy ? Milan, 20th Oct 2007

OWASP Italy

CROSS SITE SCRIPTING ? CRASH COURSE



Last messages: Foo said: hello world

SMAU E-Academy ? Milan, 20th Oct 2007

OWASP Italy

CROSS SITE SCRIPTING ? CRASH COURSE

? id=foo&message=hello">alert("Hello")

Last messages: Foo said: hello

SMAU E-Academy ? Milan, 20th Oct 2007

OWASP Italy

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download