Login or register
SecDocs RSS feed

Paper details

Title XSS Street-Fight: The Only Rule Is There Are No Rules
Type Paper
Tags XSS
Abstract Defending web applications from Cross-Site Scripting (XSS) attacks is extremely challenging, especially when the application's code can not be updated to fix the issue. This presentation will provide a walk-through of various XSS attack/defense/evasion lessons learned by Trustwave's SpiderLabs Research Team while working with commercial WAF customers, as well as, by receiving thousands of attacks against our public ModSecurity demonstration page. We will highlight cutting-edge XSS protection methods that are external to the web application's code such as Defensive Javascript Content Injection.
Authors Ryan C. Barnett
Submitted April 11, 2011
Rating
Currently 0/5 stars (0 votes).
Correlation
Linked to
Event Black Hat DC 2011
Resource ---
Download
Source BlackHat_DC_2011_Barnett_XSS%20Streetfight-wp.pdf
Size 1 MB
MD5 2606fa6d9ada9d43ede038af6cf8792f
SHA1 2077d74b28e7ad5d9906c7988177c74822fa02b1

Comments
No comments.
Add new Only logged in users can comment.


Click here to lend your support to: SecDocs and make a donation at www.pledgie.com !