This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of ".NET AntiXSS Library"

From OWASP
Jump to: navigation, search
Line 5: Line 5:
 
Cross site scripting (XSS) continues to show up on the [[Category:OWASP_Top_Ten_Project|OWASP Top Ten Project]] as a top vulnerability every year.  While very pervasive and dangerous, this vulnerability is possible to mitigate with reasonable developer effort.  This page is dedicated to helping mitigate this vulnerability in regards to the Microsoft .NET Framework.
 
Cross site scripting (XSS) continues to show up on the [[Category:OWASP_Top_Ten_Project|OWASP Top Ten Project]] as a top vulnerability every year.  While very pervasive and dangerous, this vulnerability is possible to mitigate with reasonable developer effort.  This page is dedicated to helping mitigate this vulnerability in regards to the Microsoft .NET Framework.
  
== Challenges ==
+
== Attack Vectors ==
  
 
The primary XSS attack vectors are:
 
The primary XSS attack vectors are:
 
* Reflected XSS
 
* Reflected XSS
 
* Persistent XSS   
 
* Persistent XSS   
 +
Please see [[Cross-site_Scripting_(XSS)#Stored and Reflected XSS Attacks|Cross-site Scripting (XSS)]] for more detail regarding reflected and persistent XSS attacks.
 
      
 
      
 
== Options ==
 
== Options ==
Line 22: Line 23:
  
 
== XSS References ==
 
== XSS References ==
 +
* https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)
 
* http://www.troyhunt.com/2010/05/owasp-top-10-for-net-developers-part-2.html
 
* http://www.troyhunt.com/2010/05/owasp-top-10-for-net-developers-part-2.html
 
* http://www.troyhunt.com/2011/12/free-ebook-owasp-top-10-for-net.html
 
* http://www.troyhunt.com/2011/12/free-ebook-owasp-top-10-for-net.html

Revision as of 04:07, 23 April 2014

NOTE: This content is a work in progress and all contribution is welcome. Please contact Jeff Knutson with questions, ideas, corrections, etc.

Overview

Cross site scripting (XSS) continues to show up on the as a top vulnerability every year. While very pervasive and dangerous, this vulnerability is possible to mitigate with reasonable developer effort. This page is dedicated to helping mitigate this vulnerability in regards to the Microsoft .NET Framework.

Attack Vectors

The primary XSS attack vectors are:

  • Reflected XSS
  • Persistent XSS

Please see Cross-site Scripting (XSS) for more detail regarding reflected and persistent XSS attacks.

Options

XSS References

TODO

Now

  • Look at the Microsoft implementations
  • See what work has already been done in the OWASP space for XSS
  • See what other work has been done for XSS (both .NET and other technology stacks)
  • Illustrate vulnerabilities and how to mitigate them (e.g. WebGoat.NET)
  • See if we can get the OWASP Anti-Samy project back into relevance

Future

  • Dream big here!