Friday, September 19, 2014

Exploits Of A Technical Writer

from here and here

When I heard that Amazon had an XSS vulnerability involving such things as book titles, I knew I wanted to make a tribute to Randall Munroe's "Exploits Of A Mom". Little Bobby Tables has done so much to raise awareness of SQLi vulnerabilities, why shouldn't XSS get some attention too? Especially with Amazon dropping the ball and proving they belong to Generation XSS, then a few days later news of an XSS vulnerability in the DNS lookup site, and now we find out even eBay has had an XSS vulnerability being actively used to steal user credentials for the better part of a year.

The question you need to ask yourself now is, are you a GenXSS'er as well?