Paper: RealWord XSS

[email protected] Mon, 24 Mar 2003 19:41:43 GMT
Newsgroups gmane.comp.security.papers
Message-ID <[email protected]>

In depth 20 page paper covering most aspects of XSS attacks including
injection points, attack scenarios, attacker motivations and techniques.

Includes code obfuscation examples, form event stealing, filter evasion
techniques and starts laying a foundation on a proper filtering framework. 

Included in the paper is a small package of custom developed XSS software
utilities useful for the experimentation and understanding of XSS attacks.

Paper is available as HTML, TXT and CHM formats:

http://sandsprite.com/Sleuth/papers/RealWorld_XSS_1.html
http://sandsprite.com/Sleuth/papers/XSS-Paper.txt
http://sandsprite.com/Sleuth/papers/RealWorld_XSS.chm