OWASP Appsec Tutorial Series - Episode 3: Cross Site Scripting (XSS)

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
32,987
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jul 11, 2011

The third episode in the OWASP Appsec Tutorial Series. This episode describes the #2 attack on the OWASP top 10 - Cross-Site Scripting (XSS). This episode illustrates three version of an XSS attack: high level, detailed with the script tag, and detailed with no script tag, and then recommends resources for further learning.

Link to this comment:

Share to:
see all

All Comments (23)

Sign In or Sign Up now to post a comment!
  • When will you be adding more videos? Please add more soon!

  • to the example 2- xss without script tags: so ok, you put your name into your inputbox and then onmouseover event after the quotes. and then what? it's not like other users saw this specific input box. the only person who sees this and can hover mouse over the input button is ONLY the attacker. if you submit the name, server would probably just take the name value

    am i missing something?

  • Subbed! "OWASP" was mentioned in a recent thread on the pen-test-securityfocus email list, so I checked out your website.

  • Great , if you tell us what you want to cover in next episodes we can contribute :)

  • What tool is being used to animate the text? I really like how you show user input going into the HTML @7:25

    Really good videos and easy to understand

  • Excellent Video!!!

  • Subbed....

  • GREAT!GREAT!GREAT!

    When we can to expect new episode?

    

  • You videos is amazing

  • very good, quality, simplicity..........thanks a lot

    emilio

    zaragoza

    spain

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more