<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>dotvoid.com &#187; xss</title>
	<atom:link href="http://www.dotvoid.com/tag/xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dotvoid.com</link>
	<description>Experiments and thoughts in PHP and javascript</description>
	<lastBuildDate>Tue, 11 Oct 2011 12:49:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Cross site scripting</title>
		<link>http://www.dotvoid.com/2005/10/cross-site-scripting/</link>
		<comments>http://www.dotvoid.com/2005/10/cross-site-scripting/#comments</comments>
		<pubDate>Wed, 26 Oct 2005 08:19:13 +0000</pubDate>
		<dc:creator>Danne</dc:creator>
				<category><![CDATA[Javascript]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.commodi.com/?p=154</guid>
		<description><![CDATA[While looking around for cross site scripting resources I stumbled upon this &#8220;ha.ckers.org&#8221; site which is an excellent source for ideas on how to check for XSS vulnerabilities. I have seen it before but I obviously forgot to bookmark it. Now I saw the site listed in the top of  del.icio.us/tag/xss as well. Another good [...]]]></description>
			<content:encoded><![CDATA[<p>While looking around for cross site scripting resources I stumbled upon <a href="http://ha.ckers.org/xss.html">this &#8220;ha.ckers.org&#8221; site</a> which is an excellent source for ideas on how to check for XSS vulnerabilities. I have seen it before but I obviously forgot to bookmark it. Now I saw the site listed in the top of  <a href="http://del.icio.us/tag/xss">del.icio.us/tag/xss</a> as well. Another good site to checkout is the <a href="http://www.owasp.org/">http://www.owasp.org</a> and even though their <a href="http://www.owasp.org/software/validation.html">regex collection</a> is not very international it can be useful.</p>
<p>The most annoying thing is that the only user input I allow on my site, the comment form, is vulnerable. I guess I will have to fix that now. Immediately.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-comfeed">
			<a href="http://www.dotvoid.com/2005/10/cross-site-scripting/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.dotvoid.com/2005/10/cross-site-scripting/&amp;title=Cross+site+scripting" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.dotvoid.com/2005/10/cross-site-scripting/&amp;t=Cross+site+scripting" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.dotvoid.com/2005/10/cross-site-scripting/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.dotvoid.com/2005/10/cross-site-scripting/&amp;title=Cross+site+scripting&amp;summary=While%20looking%20around%20for%20cross%20site%20scripting%20resources%20I%20stumbled%20upon%20this%20%22ha.ckers.org%22%20site%20which%20is%20an%20excellent%20source%20for%20ideas%20on%20how%20to%20check%20for%20XSS%20vulnerabilities.%20I%20have%20seen%20it%20before%20but%20I%20obviously%20forgot%20to%20bookmark%20it.%20Now%20I%20saw%20the%20site%20listed%20in%20the%20top%20of%C2%A0%20del.icio.us%2Ftag%2Fxss%20&amp;source=dotvoid.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-plaxo">
			<a href="http://www.plaxo.com/?share_link=http://www.dotvoid.com/2005/10/cross-site-scripting/" rel="nofollow" class="external" title="Share this on Plaxo">Share this on Plaxo</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.dotvoid.com/2005/10/cross-site-scripting/&amp;title=Cross+site+scripting" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Cross+site+scripting+-+http://b2l.me/wy3cu&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.dotvoid.com/2005/10/cross-site-scripting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

