<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: ciac]]></title>
    <link>http://securityratty.com/tag/ciac</link>
    <description></description>
    <pubDate>Tue, 10 Jun 2008 06:21:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[CIAC Tech Bulletin on XSS a valuable reference]]></title>
      <link>http://securityratty.com/article/14d768c1277ece67ce8d1db383a0b2a2</link>
      <guid>http://securityratty.com/article/14d768c1277ece67ce8d1db383a0b2a2</guid>
      <description><![CDATA[The only fault I could possibly find in the recently released CIAC Technical Bulletin, CIACTech08-003: Understanding Cross-Site Scripting (XSS) , is that it should have been released a year ago or...]]></description>
      <content:encoded><![CDATA[The only fault I could possibly find in the recently released <a href="http://www.ciac.org">CIAC</a> Technical Bulletin, <a href="http://www.ciac.org/ciac/techbull/CIACTech08-003.shtml">CIACTech08-003: Understanding Cross-Site Scripting (XSS)</a>, is that it should have been released a year ago or more. ;-)<br />But rather than nitpick, I'd like to applaud. <br />This is a fine effort, with a number of good resources cited.<br />You'll find content on the types of cross-site scripting, including DOM, non-persistent, persistent, and CSRF. Additionally, you'll note methods of protection and reference links to content on <a href="http://us.php.net/htmlspecialchars">Htmlspecialchars</a>, <a href="http://us3.php.net/htmlentities">Htmlentities</a>, and Giorgio Maone's <a href="http://noscript.net/">NoScript</a>. <br />This is a great starting point for enlightening vendors, developers, and IT folk who may not be as up to speed as you might like on the concerns caused by XSS vulnerabilities.<br />Given the fact that stories continue to surface on the shortcomings of major <a href="http://www.xssed.com/news/72/Verisign_McAfee_and_Symantec_sites_can_be_used_for_phishing_due_to_XSS/">security</a> <a href="http://www.darkreading.com/document.asp?doc_id=155995">vendors</a>, and their utter lack of diligence with regard to XSS, as well as efforts to further <a href="http://holisticinfosec.org/content/view/69/1/">enlighten</a> the masses, this is a valiant effort. <br />Well done, CIAC.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/06/ciac-tech-bulletin-on-xss-valuable.html&title=CIAC%20Tech%20Bulletin%20on%20XSS%20a%20valuable%20reference " title="CIAC Tech Bulletin on XSS a valuable reference">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/06/ciac-tech-bulletin-on-xss-valuable.html" title="CIAC Tech Bulletin on XSS a valuable reference ">digg</a>]]></content:encoded>
      <pubDate>Tue, 10 Jun 2008 06:21:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ciac">ciac</category>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <category domain="http://securityratty.com/tag/xss vulnerabilities">xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/ciac technical bulletin">ciac technical bulletin</category>
      <category domain="http://securityratty.com/tag/major security vendors">major security vendors</category>
      <category domain="http://securityratty.com/tag/stories continue">stories continue</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/fine effort">fine effort</category>
      <source url="http://holisticinfosec.blogspot.com/2008/06/ciac-tech-bulletin-on-xss-valuable.html">CIAC Tech Bulletin on XSS a valuable reference</source>
    </item>
  </channel>
</rss>
