Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

August 20th, 2012, 20:31 GMT · By

BLOG

Security Expert Explains the Risks Posed by XSS Flaw on Shopping Sites (Video)

SHARE:

Adjust text size:


After trying to get Tesco to fix the security holes that could expose its online shoppers, software architect and Microsoft MVP Troy Hunt has made a video to demonstrate the risks that hide behind the classic cross-site scripting (XSS) vulnerabilities.

The video and the blog post in which the expert explains everything are inspired by the presence of an XSS vulnerability on the site of the retailer.

To prove his point, Hunt has created an apparently secure website which demonstrates the dangers that lie behind unfiltered user inputs, and outputs that are not properly encoded.

The researcher also highlights the risks posed by sites that don’t flag cookies as “HTTP only.”

Users should take a look at this video to know what to look for on a shopping site to see if it’s secure. Developers, on the other hand, should learn how to create websites that don't expose their customers to risks.
FILED UNDER:
video
advisory
XSS

TELL US WHAT YOU THINK:

1,046 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


ICO to Investigate Online Security Practices of Tesco

Multiple Web Vulnerabilities Identified in SonicWALL Email Security (Video, Updated)

Persistent XSS Vulnerability Found on Tumblr (Updated)

WhiteHat: XSS Most Prevalent Site Vulnerability in 2011

Menshn Co-Founder Says Site Is Secure, Experts Try to Prove Him Wrong

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM