May 2007
Just a quick note to announce the start of dotnetids, a port of phpids [...]
This morning I knocked up some proof of concept code to illustrate the [...]
Added a tutorial on XSS and a permanent link to the String.fromCharCod [...]
This page is designed to give an overview of Cross Site Scripting atta [...]
Enter JavaScript in the box below and press "encode":
eval(String.f [...]
GNUCITIZEN has been going on about this for some time now, but the tru [...]
ha.ckers are reporting that their book on Cross Site Scripting has fin [...]
Stefano Di Paola presented an interesting paper on Flash security at O [...]
Purpose of this Month of Bugs is a demonstration of real state with s [...]
As the title says, heise Security have found a backdoor in the Artmedi [...]
kishord today presents a tool, called XSS in eXceSS and hosted by .mar [...]
Just a quick note to point out this invaluable resource for those inte [...]
For those who haven't yet seen this, .mario and christ1an over at sla. [...]
Here is a nice tool for encoding JavaScript into eval(String.fromCharC [...]
pdp has an interesting post from last month about amendments to the Br [...]
ASP.NET comes preloaded with some default XSS protection which is actu [...]
Admittedly of limited use, here is a JavaScript function I wrote to de [...]
A proposed extension to the currently supported set of ...Request obje [...]
Many sites use JavaScript methods to inject a hidden form field into 4 [...]
Today I wrote a simple tool to illustrate the binding of a Javascript [...]