18.02.2013 Views

busting-frame-busting-a-study-of-clickjacking-vulnerabilities-on-popular-sites-slides

busting-frame-busting-a-study-of-clickjacking-vulnerabilities-on-popular-sites-slides

busting-frame-busting-a-study-of-clickjacking-vulnerabilities-on-popular-sites-slides

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Reflective XSS filters<br />

• Internet Explorer 8 introduced reflective<br />

XSS filters:<br />

http://www.victim.com?var= alert(‘xss’)<br />

If alert(‘xss’); appears in the rendered<br />

page, the filter will replace it with alert<br />

(‘xss’)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!