Full Disclosure mailing list archives

Re: logically stopping xss


From: Valdis.Kletnieks () vt edu
Date: Tue, 22 Jul 2003 23:04:44 -0400

On Tue, 22 Jul 2003 21:33:00 EDT, Justin Shin <zorkshin () tampabay rr com>  said:

i know there's a lot of stupid jokes about XSS vulns right now, but I was
wondering if there is any firewall or IDS software that can look for suspicious
GET requests ... ie.

GET /vulnerablewebapp/?<XSS SHZNIT>

I'm sure there's a program out there ... and I'm stupid, please don't kill me

SNORT comes with a pretty long list....


Attachment: _bin
Description:


Current thread: