[<prev] [next>] [day] [month] [year] [list]
Message-ID: <5F9D803B30A8E4418166E637D50E9E2A0680D5@miraculix.scip.ch>
From: maru at scip.ch (Marc Ruef)
Subject: logically stopping xss
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi!
> i know there's a lot of stupid jokes about XSS vulns right
> now, but I was wondering if there is any firewall or IDS
> software that can look for suspicious GET requests ... ie.
>
> GET /vulnerablewebapp/?<XSS SHZNIT>
Watch out! Not just GET requests should be checked.
These sources should help you:
http://www.computec.ch/mruef/advisories/black_ice_pc_protection_xss_evasion.txt
http://www.securityfocus.com/bid/7942
Bye, Marc
- --
) scip AG (
Technoparkstr. 1
8005 Z?rich
T +41 1 445 18 18
F +41 1 445 18 19
maru@...p.ch
www.scip.ch
- - Aktuellste IT-Sicherheitsluecken -
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0
iQA/AwUBPx46gBe5hzJzqVMhEQLo3ACePQMjlsnO+dUyKugObsE6sBWLEDUAoORo
ZO9MgywPrJRI05CdfXba86tU
=6byH
-----END PGP SIGNATURE-----
Powered by blists - more mailing lists