1:45PM
to 3:00PM

Eduardo Vela Nava & David Lindsay: Our Favorite XSS Filters and How to Attack Them

event::type Testing
: Augustus Ballroom 3-4
About: Present several techniques that have been used, are being used, and could be used in the future to bypass, exploit and attack some of the most advanced XSS filters. These would include the new IE8 XSS Filters, browser addons (NoScript), server side IDSs (mod_security, PHP-IDS), and human log-review. We will present innovative techniques that expand the scope of what we think we know about XSS filters. We will give you some ideas on what to do to find your own based upon some real world examples, discoveries, techniques and attacks.

: Eduardo Vela Nava, David Lindsay
event::url http://www.blackhat.com/html/bh-usa-09/bh-usa-09-speakers.html#VelaNava

 


 

event::comment

 



footer::loading