Re: [Plugins-writers] Detecting XSS in script parameters

From: John Lampe (jwlampe@private)
Date: Wed Aug 04 2004 - 06:12:34 PDT


----- Original Message ----- 
From: "Paul Johnston" <paul@private>
To: <plugins-writers@private>
Sent: Wednesday, August 04, 2004 4:50 AM
Subject: [Plugins-writers] Detecting XSS in script parameters


> Hi,
> 
> I notice there is no plugin that checks for XSS in all of a forms 
> parameters, in the way wpoison.nasl checks for SQL injection. I am 
> planning to develop such a plugin and wondered if anyone had any 
> thoughts on the matter before I do so.
> 

Hi Paul,

torturecgis.nasl does (among other things) an XSS check.

John Lampe
Researcher, Tenable Network Security
http://www.tenablesecurity.com/
_______________________________________________
Plugins-writers mailing list
Plugins-writers@private
http://mail.nessus.org/mailman/listinfo/plugins-writers



This archive was generated by hypermail 2.1.3 : Wed Aug 04 2004 - 06:17:19 PDT