ScanAlert – XSS is Cool with Us

  • Post author:
  • Post category:Uncategorized

Sometimes I just want to give up. I really hate XSS because it is really a tricky issue to explain to people that do not understand. It basically boils down to bad people using my website to compromise clients. What they do with those compromised clients can range from fairly benign replicating worms, phishing scams, all the way to total remote control of the end user’s browser.

The fine folks at ScanAlert clearly do not think this is a problem though.

It is hard enough to educate web site owners that this is a problem and how it impacts them without having to fight against people in our own industry telling them it is OK to have XSS vulnerabilities.

This is the kind of thing that drives me crazy about the security industry. We have companies that are supposed to be protecting websites giving them a clean bill of health when they have basic cross-site scripting flaws. How are we supposed to make progress when the companies doing the scanning are telling people these issues do not matter?

XSS matters. It matters a lot. Stop telling people it does not.