This is a whitepaper that gives a complete cross site scripting walkthrough.
048df1139c315869c0a90ee93b3e41e7Whitepaper called Overview to HTML5 web security. This article is an extract of the master thesis written by Michael Schmidt. It needs to be considered that the content of this document was released in May 2011.
6a2459e2a9cb59dbfd3c58001f6d83c4This is a whitepaper called the Beginner's Guide To Cross Site Scripting.
c74c78d3203d725fb79b8fb083d742baWhitepaper discussing cross site scripting, bypassing techniques, and the usefulness of these attacks.
4a551ec6dc2e708d3cc8bdc937e9802aThis is a whitepaper discussing the risk associated with the privacy of your data on Facebook.
77644050c700d33c017cc6fb00171acdWhitepaper called XSS Street-Fight: The Only Rule Is There Are No Rules.
2606fa6d9ada9d43ede038af6cf8792fWhitepaper called Session Hijacking Basics.
4f9d1dc616b049a5b82564cd89077ac7Whitepaper called Introduction to Cross Site Request Forgery. Written in Persian.
eefc0e55d464289d49d50c97dc6d11bcThis is a whitepaper on cross site scripting written in German.
3cb1ed1823303efb53b8c1eeae2b5780Whitepaper called Weaning The Web Off Of Session Cookies. It compares the security weaknesses and usability limitations of both cookie-based session management and HTTP digest authentication; demonstrating how digest authentication is clearly the more secure system in practice.
9469a3766c681c802663697fe6cb6347Whitepaper called Security of the Web. This papers discusses how vulnerabilities have evolved over the years and how web applications have become a primary vector of attack. Written in German.
2aaf20a12012c628ded7d80ceb29084eWhitepaper called Web Vulnerabilities and Security. Written in Romanian.
1b80aea5472d25649ffdb138059dcaebWhitepaper discussing how the recent addition of SSL to The Pirate Bay does not sufficiently protect users from being detected.
aece25089c072f10be4d386175cc9bcaOffensive XSS 101 - A small write up discussing basic logistics and methodologies for cross site scripting.
ff743728769e4d19e29c5c93f8b006c1Whitepaper called Client Side Security - More Severe Than It Seems. It touches on the darker side of cross site scripting and cross site request forgery along with information on how to protect against these attacks.
049b46f47c7a4da1b48f9899c3ce91ddWhitepaper discussing site wide cross site scripting which is a technique to make injected code stay resident in the user's browser even after he leaves the vulnerable URL.
ad67d31aa24de158ec36b18cb15b58d5Whitepaper from 2002 that has been updated regarding the abuse of non-HTTP protocols to launch cross site scripting attacks.
e81ed8cd8d2e8d2e1d9816c6ef6cd279Whitepaper called Bypassing URL Authentication and Authorization with HTTP Verb Tampering.
e0b28b8fd26cc5abc41183fb255c1f89Whitepaper regarding cross site request forgery attacks. Written in Spanish.
8c450745dbb41e254f73345fc61d0051The Common Criteria Web Application Security Scoring, or CCWAPSS, is a security scoring methodology for web applications. This is version 1.1.
5ea6ef8ecb7705a123ff16bb352355daWhitepaper discussing the prevention of cross site request forgery attacks.
a49ecadb951b8eee7ff28a5e3d1a0011Whitepaper entitled "XSS The Complete Walkthrough". Written to discuss how web developers should code securely to negate cross site scripting vulnerabilities.
ea0d36f530b68478686e58ee6c39852cWhitepaper describing tunneling HTTP traffic via cross site scripting channels.
6fc8c1b79fd57a8e351b1b1c8ecdbdb5DNS Pinning and Web Proxies - A white paper that describes DNS based attacks against web proxies.
029f0c78ba3708e16fbb1cc4d20b354cWhite paper titled Hack Annotations In JWIG.
40b681226ac3191504d09b30b4e0aa70