<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>How Do I Understand and Defend Against Script Injection Attacks in ASP.NET</title><link>http://asp.net</link><pubDate>Sat, 29 Oct 2011 13:34:27 GMT</pubDate><generator>umbraco</generator><description>Comments for How Do I Understand and Defend Against Script Injection Attacks in ASP.NET</description><language>en</language><atom:link href="http://asp.net/rss/comments/33531" rel="self" type="application/rss+xml" /><item><title>Comment Posted by dil4u</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Wed, 14 Oct 2009 09:04:54 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006363</guid><description><![CDATA[ <p>brilliant video....</p>]]></description><enclosure length="0" type="image/png" url="http://i1.asp.net/avatar/dil4u.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by invervegas</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Wed, 14 Oct 2009 09:07:36 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006364</guid><description><![CDATA[ <p>Awesome video, I hope we see more on this topic.</p>]]></description><enclosure length="0" type="image/png" url="http://i2.asp.net/avatar/invervegas.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by charles.f.phillips</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Wed, 14 Oct 2009 19:55:21 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006366</guid><description><![CDATA[ <p>Excellent!  I&#39;ve been &quot;JavaScripting&quot; for over a decade, but I had no idea you could be so malicious - I just learned how innocent and ignorant I really am...</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/charles.f.phillips.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by haithemara</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Thu, 15 Oct 2009 00:42:08 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006367</guid><description><![CDATA[ <p>Nice Video.</p>]]></description><enclosure length="0" type="image/png" url="http://i1.asp.net/avatar/haithemara.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by novakg</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Tue, 20 Oct 2009 20:56:06 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006368</guid><description><![CDATA[ <p>Thanks, Joe.  Now I have a *bunch* more work to do.  {sigh}</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/novakg.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by neo302</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Mon, 02 Nov 2009 20:32:54 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006369</guid><description><![CDATA[ <p>Excellent job on the video.</p>]]></description><enclosure length="0" type="image/png" url="http://i1.asp.net/avatar/neo302.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by Vishal</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Fri, 13 Nov 2009 09:01:50 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006370</guid><description><![CDATA[ <p>Brilliant video Joe, thanks a lot!</p>]]></description><enclosure length="0" type="image/png" url="http://i2.asp.net/avatar/Vishal.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by akatyal</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Fri, 12 Feb 2010 07:17:15 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006371</guid><description><![CDATA[ <p>Good job man. Thank you for enlightening simpletons like me. Makes me wonder how many innocent people out there fall prey to such attacks. But thanks to you and people like you that use the knowledge they have for the good of others. This is a great form of charity. My hat&#39;s off to you!</p><p>P.S. People that saw this video - just like Joe mentioned, in conjunction with this implement other safeguards as well available in asp.net + AJAX to control and validate the user input througout your site.</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/akatyal.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by mojara2009</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Thu, 01 Jul 2010 20:26:53 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000009292</guid><description><![CDATA[ <p>Wow this is really informative so far.</p>]]></description><enclosure length="0" type="image/png" url="http://i1.asp.net/avatar/mojara2009.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by chullos</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Sat, 31 Jul 2010 19:21:17 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000009708</guid><description><![CDATA[ <p>Dear Joe!</p><p></p><p>Hi, thank you for this great video, will be great you can add another videos giving us more real techniques to apply and tell us how to create the customized paged for the unhundled exception. Thank you.</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/chullos.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by lilmammal</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Wed, 15 Dec 2010 14:22:12 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-0000000011205</guid><description><![CDATA[ <p>Great video. I do have a question though. In the XSS demo using the overlay - how is this a threat to other users? Wouldn&#39;t this malicious credit card phish control only display in the attacker&#39;s browser?</p>]]></description><enclosure length="0" type="image/png" url="http://i2.asp.net/avatar/lilmammal.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by scal</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Thu, 07 Jul 2011 11:04:30 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-0000000013719</guid><description><![CDATA[ <p>Great video and &#39;quick&#39; (yes, there is much much more to teach/learn in the subject) presentation.</p><p>@lilmammal: the script that does the overlay + send ajax to store the CC info is stored into a DB and executed at rendering of the page, so it renders for all people visiting that page. </p><p>It would only stop executing if the shout-box was to display only the latest X shouts, and there were at least X new shouts after the malicious one.</p>]]></description><enclosure length="0" type="image/png" url="http://i1.asp.net/avatar/scal.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by olo21</title><link>http://asp.net/web-forms/videos/how-do-i/how-do-i-understand-and-defend-against-script-injection-attacks-in-aspnet</link><pubDate>Sat, 29 Oct 2011 13:34:27 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-0000000014518</guid><description><![CDATA[ <p>&lt;b&gt;Great video&lt;/b&gt;</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/olo21.jpg?forceidenticon=false&amp;dt=635049037200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item></channel></rss>