Wednesday

Paper: XSIO "Cross Site Image Overlaying"


Ok, I know XSS, CSRF etc..... but I never hear about XSIO.

A new paper on a vulnerability called XSIO. XSIO stands for "Cross Site Image Overlaying" and is basically the same as XSS except there is no scripting involved, but instead an image is referenced and positioned using CSS over an important part of a website. (SANS ISC)

Thanks Swa!

Also, check out the OWASP Top Ten 2007 if you never have.

0 comments: