Hands On Series Postings

Hands On Series – Cross Site Scripting (XSS) Part 1

August 28th, 2006

The “Hands on Series” continues!

 
icon for podpress  Standard Podcast [38:10m]: Play Now | Play in Popup | Download

In this episode we start dealing with Cross Site Scripting (XSS) attacks.

CSS = Cascading Style Sheets
XSS = Cross Site Scripting

Cross Site Scripting is a technique used to add script to a trusted site that will be executed on other users browsers.
A key element to XSS is that one user can submit data to a website that will later be displayed for other users.
It is nessesary that the bad guy NOT mess up the HTML structure, otherwise the result will be web defacement rather then attacking other users.

The hackme site has been updated and improved (more about that in a moment)

and now includes a section for XSS which we will be using in this episode.

Read the rest of this entry »

Hands On Series – SQL Injection Part 1

April 28th, 2006

The start of the “Hands on Series”, which means that there are actual
hands on excersises to go along with these shows.

 
icon for podpress  Standard Podcast [58:03m]: Play Now | Play in Popup | Download

 
icon for podpress  Code Monkey - Played during podcast [3:07m]: Play Now | Play in Popup | Download

I feel that its time to go beyond the concepts, the chatter about what bad guys can do,
and actually show you directly. Let you see for yourself the saying goes.

I recommend that you listen to these episodes while viewing the hacking test site and
have the show notes visible and ready to cut and paste from.

Read the rest of this entry »

 
Mighty Seek Podcast, MightySeek Podcast, Mighty Seek Blog, MightySeek Blog, Web application security podcast, Web application security blog, Web application development blog, Web application development podcast