(Almost) All Your (BASE) Are Belong to Us!

Thursday, December 01, 2011

Contributed by Bouke van Laethem

The HTML element Cross Site Scripting (XSS) I will discuss abuses the "best practice" among web developers to use relative links and the tendency of web browsers to parse incorrect HTML.

HTML tags are often used in Cross Site Scripting (XSS) attacks. Usually they help an attacker inject dangerous javascript or html content.

The element XSS works a little different. Instead of creating its own injections, it hijacks normal requests for resources, loading these from an attacker's server. Form data which was meant to stay in the application, will end up at the attacker's server as well.

Information Security
XSS Javascript Application Security HTML Attacks Cross Site Scripting hackers Code Injection uniform resource identifier
