Examining And Bypassing The IE8 XSS Filter - Presentation Transcript
Examining and Bypassing the IE8 XSS Filter Alex Kouzemtchenko [email_address]
About Me
SIFT
http://www.sift.com.au/
Independent information security services
Alex Kouzemtchenko
[email_address]
R&D Team Lead & Associate
Focus on Offensive Security Research
Internet Hardman & Conference Mercenary in another life
Disclaimer
This talk is presented from the adversary’s point of view
This isn’t meant to be a diss on Microsoft or David Ross
The XSS Filter is a step in the right direction
XSS attacks which don’t take it into account will fail
Lifts the bar higher, RC1 even blocks huge chunks
This talk is specifically about the IE8 Beta 2 and IE8 RC1 filters
While I’ve been in communication with Microsoft about these issues, I don’t know what the final release will look like, most of these should hopefully be fixed
Agenda
XSS Filter Goal & Rationale
Filter Design & Overview
Protected & Un-Protected Scenarios
Some Implementation Details
Bypasses for various scenarios
Where the filter is effective
Summary
XSS Filter Goals & Rationale
XSS is the most reported bug class today
Even in frameworks which do a lot to protect apps
Still common, even in well known and audited sites
“ Type-1 XSS flaws … are increasingly being exploited “for fun and profit.” ” – David Ross
One of the easiest vulnerabilities to exploit
Known by every beginning hacker out there
Nice avenue for attacks if you’re willing to sacrifice your pride
Mass-exploitation has begun – IFRAME SEO Poisoning
0 comments
Post a comment