lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <200601281252.47274.netsys@machine.org.uk> Date: Sat Jan 28 12:53:11 2006 From: netsys at machine.org.uk (Tim Brown) Subject: Misunderstanding Javascript injection: A paper on web application abuse via Javascript injection Hi, I've just released a paper (to be found at http://www.nth-dimension.org.uk/news/entry.php?e=156579087) which covers two issues with Javascript injection that I've recently been playing with. That of Javascript injection via CSS manipulation and further more the use of AJAX within injection points. I realise that perhaps neither are massively new (certainly the MySpace worm touches on the AJAX issues discussed) but I found it interesting and hope others may do too. Tim -- Tim Brown <mailto:tmb@...35.com> -- Tim Brown <mailto:netsys@...hine.org.uk> <http://www.machine.org.uk/>