<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: VIDEO: web application firewall bypass with a XSS attack</title>
	<atom:link href="http://www.acunetix.com/blog/news/web-application-firewall-bypass-xss-attack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.acunetix.com/blog/news/web-application-firewall-bypass-xss-attack/</link>
	<description>Acunetix Web Application Security Blog</description>
	<lastBuildDate>Fri, 10 Feb 2012 07:58:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Greg Howe</title>
		<link>http://www.acunetix.com/blog/news/web-application-firewall-bypass-xss-attack/#comment-6013</link>
		<dc:creator>Greg Howe</dc:creator>
		<pubDate>Wed, 09 Jun 2010 14:58:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=1596#comment-6013</guid>
		<description>Another case of developers (in this case at the web app firewall vendor) not encoding output to the screen.  They trusted the input and spit it back out.  XSS is an old attack and easy to thwart.

This goes to show that even security-conscious folks don&#039;t yet have a complete grasp of the size of the battlefield.  Encode EVERY output.  Anything that goes to screen, log files, event logs, whatever.  You don&#039;t know how they will be used.  There are lots of log file readers that display the data to the screen.  Encode it first.

Great video, nice job showing how it works and getting people in the loop about the issue.  I hope we will see more of this and more professional developers will shore up their code!</description>
		<content:encoded><![CDATA[<p>Another case of developers (in this case at the web app firewall vendor) not encoding output to the screen.  They trusted the input and spit it back out.  XSS is an old attack and easy to thwart.</p>
<p>This goes to show that even security-conscious folks don&#8217;t yet have a complete grasp of the size of the battlefield.  Encode EVERY output.  Anything that goes to screen, log files, event logs, whatever.  You don&#8217;t know how they will be used.  There are lots of log file readers that display the data to the screen.  Encode it first.</p>
<p>Great video, nice job showing how it works and getting people in the loop about the issue.  I hope we will see more of this and more professional developers will shore up their code!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#8230;&#8230;&#8230;..und der Admin hyperventilierte &#187; Blog Archive &#187; Die besten, interessantesten, wichtigsten und unterhaltsamsten Artikel aus der Security-Branche.</title>
		<link>http://www.acunetix.com/blog/news/web-application-firewall-bypass-xss-attack/#comment-5997</link>
		<dc:creator>&#8230;&#8230;&#8230;..und der Admin hyperventilierte &#187; Blog Archive &#187; Die besten, interessantesten, wichtigsten und unterhaltsamsten Artikel aus der Security-Branche.</dc:creator>
		<pubDate>Mon, 07 Jun 2010 15:53:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=1596#comment-5997</guid>
		<description>[...] web application firewall bypass with a XSS attack – acunetix.com Video-Demonstration zur Aushebelung von dotDefender&#8230;.. [...]</description>
		<content:encoded><![CDATA[<p>[...] web application firewall bypass with a XSS attack – acunetix.com Video-Demonstration zur Aushebelung von dotDefender&#8230;.. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Week 22 in Review &#8211; 2010 &#124; Infosec Events</title>
		<link>http://www.acunetix.com/blog/news/web-application-firewall-bypass-xss-attack/#comment-5996</link>
		<dc:creator>Week 22 in Review &#8211; 2010 &#124; Infosec Events</dc:creator>
		<pubDate>Mon, 07 Jun 2010 06:50:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=1596#comment-5996</guid>
		<description>[...] web application firewall bypass with a XSS attack &#8211; acunetix.com In the following demo video, Sandro Gauci of EnableSecurity shows how an attacker can switch off dotDefender in order to bypass any “protection” offered by the WAF.   [...]</description>
		<content:encoded><![CDATA[<p>[...] web application firewall bypass with a XSS attack &#8211; acunetix.com In the following demo video, Sandro Gauci of EnableSecurity shows how an attacker can switch off dotDefender in order to bypass any “protection” offered by the WAF.   [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul</title>
		<link>http://www.acunetix.com/blog/news/web-application-firewall-bypass-xss-attack/#comment-5987</link>
		<dc:creator>Paul</dc:creator>
		<pubDate>Wed, 02 Jun 2010 10:52:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=1596#comment-5987</guid>
		<description>Great video and another good bit of information from Acunetix. I use your web scanner and recommend it to all my customers and also run tests on any websites that I build. Thanks and keep up the great work :)</description>
		<content:encoded><![CDATA[<p>Great video and another good bit of information from Acunetix. I use your web scanner and recommend it to all my customers and also run tests on any websites that I build. Thanks and keep up the great work <img src='http://www.acunetix.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Web application firewall bypass with a XSS attack &#124; SkemTech Blog</title>
		<link>http://www.acunetix.com/blog/news/web-application-firewall-bypass-xss-attack/#comment-5981</link>
		<dc:creator>Web application firewall bypass with a XSS attack &#124; SkemTech Blog</dc:creator>
		<pubDate>Tue, 01 Jun 2010 19:20:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=1596#comment-5981</guid>
		<description>[...] info and video demo: http://www.acunetix.com    Tags: checking-out, doors, dotdefender, from-the-below, having-secure, sandro-gauci, [...]</description>
		<content:encoded><![CDATA[<p>[...] info and video demo: <a href="http://www.acunetix.com" rel="nofollow">http://www.acunetix.com</a>    Tags: checking-out, doors, dotdefender, from-the-below, having-secure, sandro-gauci, [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

