<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.networkworld.com/community" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>cross site scripting</title>
 <link>http://www.networkworld.com/community/taxonomy/term/7241</link>
 <description>Showing new posts in a forum view</description>
 <language>en</language>
<item>
 <title>The CIA Hack...still working.</title>
 <link>http://www.networkworld.com/community/node/27093</link>
 <description>Once &lt;a href=&quot;http://blog.wired.com/27bstroke6/2008/04/cia-copies-thre.html&quot;&gt;this&lt;/a&gt; vulnerability was submitted by &lt;a href=&quot;http://piru.dyndns.org/~p&quot;&gt;Harry Sintonen&lt;/a&gt; to Wired&amp;#39;s Threat Level last week, it&amp;#39;s been spreading like wildfire throughout the web.  Discovery of a new XSS is nothing new, but &lt;em&gt;does&lt;/em&gt; become noteworthy when it involves a domain like CIA.gov.  While not a site 0wning exploit, it &lt;em&gt;is&lt;/em&gt; an embarrassing example of poor input validation.  &lt;p&gt;A search form at their site provides the unfiltered option to inject script running character strings.  The query is processed and your customized site appears (at least that seems to be what most people are using it for-for those with more malicious intent....good luck, you&amp;#39;ll probably win a free ride  &lt;span class=&#039;read-more&#039;&gt;&lt;a href=&quot;http://www.networkworld.com/community/node/27093&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Read more&lt;/strong&gt;&lt;/a&gt;&lt;/span&gt;</description>
 <comments>http://www.networkworld.com/community/node/27093#comments</comments>
 <category domain="http://www.networkworld.com/community/taxonomy/term/16">Security</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/4913">CIA</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/7241">cross site scripting</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/5294">cross-site scripting</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/9838">exploit</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/3700">government</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/454">hack</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/11295">input validation</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/562">search</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/58">security</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/7509">security vulnerabilities</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/1928">US goverment</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/4677">vulnerability</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/7808">XSS</category>
 <pubDate>Mon, 21 Apr 2008 10:36:22 -0400</pubDate>
 <dc:creator>Noah Schiffman</dc:creator>
 <guid isPermaLink="false">27093 at http://www.networkworld.com/community</guid>
</item>
<item>
 <title>IBM software attacks critical application security issues</title>
 <link>http://www.networkworld.com/community/node/21855</link>
 <description>&lt;p&gt;IBM today introduced software it says will help customers protect Web applications from attack, particularly from the nefarious  &quot;&lt;a href=&quot;/news/2007/100407-web-site-vulnerabilities.html&quot;&gt;cross site request forgery&lt;/a&gt;&quot; in which an &lt;a href=&quot;/community/node/19079&quot;&gt;attacker can fake a request&lt;/a&gt; to a site gaining access to sensitive information.  &lt;span class=&#039;read-more&#039;&gt;&lt;a href=&quot;http://www.networkworld.com/community/node/21855&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Read more&lt;/strong&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;</description>
 <comments>http://www.networkworld.com/community/node/21855#comments</comments>
 <category domain="http://www.networkworld.com/community/taxonomy/term/29">Data Center</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/33">E-commerce</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/1035">General discussions</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/16">Security</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/17">Software</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/7242">cross site request forgery</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/7241">cross site scripting</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/231">IBM</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/7243">Rational Appscan</category>
 <category domain="http://www.networkworld.com/community/taxonomy/term/7240">Watchfire</category>
 <pubDate>Tue, 13 Nov 2007 10:32:48 -0500</pubDate>
 <dc:creator>Layer 8</dc:creator>
 <guid isPermaLink="false">21855 at http://www.networkworld.com/community</guid>
</item>
</channel>
</rss>
