The third episode in the OWASP Appsec Tutorial Series. This episode describes the #2 attack on the OWASP top 10 - Cross-Site Scripting (XSS). This episode illustrates three version of an XSS attack: high level, detailed with the script tag, and detailed with no script tag, and then recommends resources for further learning.
When will you be adding more videos? Please add more soon!
secureworks 1 week ago
to the example 2- xss without script tags: so ok, you put your name into your inputbox and then onmouseover event after the quotes. and then what? it's not like other users saw this specific input box. the only person who sees this and can hover mouse over the input button is ONLY the attacker. if you submit the name, server would probably just take the name value
am i missing something?
seriouslyWeird 3 weeks ago
Subbed! "OWASP" was mentioned in a recent thread on the pen-test-securityfocus email list, so I checked out your website.
1fishkungfu 3 months ago
Great , if you tell us what you want to cover in next episodes we can contribute :)
MrM4X0N3 3 months ago
What tool is being used to animate the text? I really like how you show user input going into the HTML @7:25
Really good videos and easy to understand
ambroseLeung 4 months ago in playlist More videos from AppsecTutorialSeries
Excellent Video!!!
luismartineztx 4 months ago
Subbed....
conspiritor2 4 months ago
GREAT!GREAT!GREAT!
When we can to expect new episode?
axePK 4 months ago
You videos is amazing
abhushanshrestha 5 months ago
very good, quality, simplicity..........thanks a lot
emilio
zaragoza
spain
emilioastier 5 months ago