Misunderstanding Javascript Injection: A Paper on Web Application Abuse Via Javascript Injection (2006)

 

 

Whilst it is common to see the issue of Javascript injection on the various security oriented mailing lists, there are issues I’ve not seen much mention of, this paper seeks to rectify that. This paper seeks to make three key points: 1. To successfully inject, doesn’t require javascript: or the <script> tag. 2. After successful injection, stuff the cookie, AJAX gives more room to move. 3. Web browsers shouldn’t be able to read and write client’s clipboards. [via]
http://www.nth-dimension.org.uk/pub/MUJSI.pdf...

Rating: 0/10

 

 

 

Related Files

 

 
Sponsored Links
Free Download MultiTech Manual, Guide, Instructions, available in PDF ebooks format.
Misunderstanding Javascript Injection: A Paper on Web Application Abuse Via Javascript Injection

Rate this Document

ADS

 

Tag Clouds

 

Last Download

 

BookShelf