Web Hack List

Top 10 winner

Our Favorite XSS Filters and how to Attack them

A recap of the Black Hat USA 2009 talk on breaking XSS filters, pointing at the slides and a co-presenter's write-up. It records a fixed Google imgres same-origin exception, a PHP 4/5/6 utf8_decode flaw enabling filter bypasses, a NoScript denial of service, a PHPIDS bypass, and the author's client-side Active Content Signatures proposal.

Record

Researcher
sirdarckcat
Published by
sirdarckcat.blogspot.com
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of sirdarckcat, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .