Cross-site scripting (XSS) attacks, a method by which attackers embed HTML scripts either in Web postings (stored XSS) or input fields on a Web site (reflected XSS), are gaining popularity, most likely due to the relative ease with which they can be executed on unwitting victims. You can assess the vulnerability of your Web site using the Open Web Application Security Project's WebGoat utility. This download explains how attackers use XSS and how you can protect yourself from cross-site scripting.
Have you had to fend off cross-site scripting attacks on your Web site?
Related white papers
UPS Security Technology Group Uses Web-Based Technology to Produce ID Cards, Saving Local Departments From Purchasing Expensive Systems
In the immediate days after 9/11, UPS drivers were being denied entry into military installations and government buildings and faced increased delivery delays due to heightened security approvals and escorts....
The MyDoom Worm
An e-mail worm continued to clog Internet traffic this week, spreading faster than previous Web bugs by appearing as an innocuous error message. The worm - dubbed "MyDoom," "Novarg" or...
Cross Site Scripting Explained
This white paper briefs on how to stop Cross Site Scripting (CSS) attacks. It details the entire CSS technique and methods for securing a site against CSS attacks.
Attacks and Countermeasures: A Study of Network Attack Classes and Security Components to Protect Against Them
There are many types of network attacks, and security solutions to address almost all of them. Most attack types fall into three major categories: attacks on integrity, attacks on confidentiality...
Trojan Defence: A Forensic View
The Trojan defence; “I didn’t do it, someone else did”– myth or reality? This two part article investigates the fascinating area of Trojan & network forensics and puts forward...
Gene Kim Presents "Surviving and Benefiting from an Audit" with Craig Morgan, Partner KPMG
An audit is a necessary and often painful event for many companies. As difficult as it is to imagine, it is possible to benefit from an audit. By understanding the...
Wireless worries: Unauthorized hot spots and rogue warriors
Many businesses and educational institutions have their own wireless networks-- but are often faced with policing rogue wireless hot spots brought in by employees or students. The rogue hot spots...


