|
-
February 7th, 2008, 05:02 AM
#1
XSS: What Type of Vuln Is It?
Hey Hey,
This is actually from an older blog post that I wrote. To give you a small portion of the difference between Local and Remote vulns and my feelings, I'll quote part of it... but I'd appreciate it if people read the post and the comments... I think this could turn into a rather interesting discussion point...
Local Vulnerability: A vulnerability affecting a client, generally you can think of this as falling into two types. Type 1 is physical access required and Type 2 is user interaction required.
Remote Vulnerability: A vulnerability affecting a remotely available service, or something available via that service.
So... Is XSS a local or a remote? I'll tell you that I'm fairly close-minded on this topic, so unless you've got a fairly compelling reason to argue it's a local, I'll most likely disagree. My answer is remote. Why? The XSS exists in a web page. The web page is hosted on a web server and is remotely available. To me that makes sense, I'm not sure that it can really be disagreed with. An argument for XSS being considered a local is that the client is affected... this seems to make sense. You visit a web page and a pop-up containing 'XSS' suddenly shows up but sit down and consider what happens.
Peace,
HT
Similar Threads
-
By cheyenne1212 in forum Miscellaneous Security Discussions
Replies: 7
Last Post: February 1st, 2012, 02:51 PM
-
By jerichoholic in forum Spyware / Adware
Replies: 12
Last Post: November 30th, 2004, 11:14 AM
-
By Carla in forum Web Security
Replies: 41
Last Post: October 31st, 2004, 09:17 AM
-
By dantesheaven in forum Spyware / Adware
Replies: 9
Last Post: October 24th, 2004, 01:49 PM
-
By Noble Hamlet in forum AntiOnline's General Chit Chat
Replies: 1100
Last Post: March 17th, 2002, 09:38 AM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|