tungwaiyip.info

 

home

about me

links

my software

Media

Yucatán Photos

St Lucia Photos

Photo Album

Videos

Blog

< July 2004 >
SuMoTuWeThFrSa
     1 2 3
4 5 6 7 8 910
11121314151617
18192021222324
25262728293031

past articles »

Click for San Francisco, California Forecast

San Francisco, USA

 

Checking for Cross-Site Scripting Vulnerability

Netcraft.com brings my attention to cross-site scripting security problem. I have examined this website for vulnerabilities. This problem is usually caused by systems not checking input received from user or third party before using it. One place this website receives input is the RSS new feeds. I have crafted a test RSS with embedded javascript. Some RSS feeder (including this website) display the content as is. They should have (arguably) strip off the embedded script before displaying it. I promptly plugged this by escaping the meta characters before outputting them on the web pages.

An important element for cross-site scripting is that a third party can use a reputable website as a conduit to inject questionable code in their context. In this case the news feeder's communication is only between this website and the news source. I am not aware of any loop hole for third party to get involved. But in the world of open communication it is better to be safe to test for all input before use.

2004.07.20 [, ] - comments (0)

 

 

Comments (0)

past articles »

 

BBC News

 

UN agrees DR Congo troop increase

 

No agreement for US car bail-out

 

'Experts' lead Saudi tanker talks

 

Hebron settlers desecrate mosque

 

US warned of China 'cyber-spying'

 

US judge orders Algerians freed

 

Colombian scam suspect extradited

 

Arab plan explained in Hebrew ads

more »

 

Slashdot News for nerds, stuff that matters

 

Unix Dict/grep Fixes Left-Side-of-Keyboard Puzzle (2008-11-20T22:40:00+00:00)

 

Kaminsky Bug Options Include "Do Nothing," Says IETF (2008-11-20T21:46:00+00:00)

 

Search For the Tomb of Copernicus Reaches an End (2008-11-20T21:00:00+00:00)

 

Apple DMCAs iPodHash Project (2008-11-20T20:18:00+00:00)

 

Network Neutrality — Without Regulation (2008-11-20T19:32:00+00:00)

 

Lessig, Zittrain, Barlow To Square Off Against RIAA (2008-11-20T18:47:00+00:00)

 

Study Recommends Online Gaming, Social Networking For Kids (2008-11-20T18:02:00+00:00)

 

CRTC Rules Bell Can Squeeze Downloads (2008-11-20T17:21:00+00:00)

more »

 

SF Gate

 

Calif. trains collide; no major injuries reported (20 Nov 2008)

 

Dems delay auto bailout vote, seek plan from Big 3 (20 Nov 2008)

 

Dems: Napolitano emerges for Homeland Security job (20 Nov 2008)

 

Pakistan protests to US over deep missile strike (20 Nov 2008)

 

Judge orders release of 5 terror suspects at Gitmo (20 Nov 2008)

 

Calif. cities consider green alternatives to lawns (20 Nov 2008)

 

Bay Area home prices dive, sales soar (20 Nov 2008)

 

Jobless claims jump unexpectedly to 16-year high (20 Nov 2008)

 

Dems are postponing crucial vote on auto bailout (20 Nov 2008)

 

APNewsAlert (20 Nov 2008)

 

Farming company offers to buy US Sugar (20 Nov 2008)

 

More than 5,000 Boise St. fans in Reno for weekend (20 Nov 2008)

 

The year 2025: Oil, dollar out; Russia, Islam in (20 Nov 2008)

 

Regulating swap transactions blamed for meltdown (20 Nov 2008)

more »

 

Asia Times Online

 

Tokyo itches to take on pirates (20 Nov 2008)

 

China all at sea off Africa (20 Nov 2008)

 

The jolly life of a pirate ring (20 Nov 2008)

 

The US strikes deeper in Pakistan (20 Nov 2008)

 

UMNO has stubborn staying power (20 Nov 2008)

 

Syria and Britain all ears now (20 Nov 2008)

 

Tibet movement veers from 'middle way' (20 Nov 2008)

 

China serves up mega-buck banquet (20 Nov 2008)

 

SPEAKING FREELY : The evil of the US dollar (20 Nov 2008)

 

TARP flip-flop true to form (20 Nov 2008)

 

Bankruptcy is key for Detroit survival (20 Nov 2008)

 

THE MOGAMBO GURU : Fed up with Fed credit (20 Nov 2008)

more »

 


Site feed Updated: 2008-Nov-20 14:15