Cross-Site Scripting: To Alert() and Beyond!

No ratings

Presented at BSidesNola 2017 by

Cross-Site Scripting is often reported, in the news and as findings in analysis reports. People don't always understand what is the cause, or the risk that it presents. Most proof of concepts used to demonstrate these flaws, stop with just making a message box appear. But, what is the real issue, the real risk, how far can an intruder get with a cross-site scripting vulnerability? This talk is a discussion of what the vulnerability is, and how it can be exploited featuring the following: - What is it - How does it work - How bad can it get - What can developers and security practitioners do to defend Live demos will show these attacks in action, as well as how critical the impact of these attacks can be.