The Real Danger of

XSS and CSRF are 2 sides of same coin.

XSS abuses the trust victim has on application.
12 days ago by blackthorne
thejameskyle/guarded-string: Prevent accidentally introducing XSS holes with the strings in your app
guarded-string - Prevent accidentally introducing XSS holes with the strings in your app
17 days ago by jimthedev
OWASP Top 10: Kritischer Blick auf die Charts | heise Developer
Die Entwicklung der OWASP Top 10, einer Liste von Sicherheitsrisiken, fand Ende 2017 erstmals öffentlich statt. Die Neuerungen können sich sehen lassen, boten aber auch Stoff für Diskussionen.
19 days ago by keimlink
Cross-Site Scripting (XSS) Cheat Sheet | Veracode
Cross-Site Scripting (also known as XSS) is one of the most common application-layer web attacks. XSS vulnerabilities target scripts embedded in a page that are executed on the client-side (in the user’s web browser) rather than on the server-side.
25 days ago by whip_lash
I’m harvesting credit card numbers and passwords from your site. Here’s how.
"If an attacker successfully injects any code at all, it’s pretty much game over"

very entertaining read; hilariously scary!
5 weeks ago by stijn

