Hello,
I wanted to announce that today the ACE and the ASP.NET team released V1.5 of the Anti-Cross Site Scripting Library at http://msdn2.microsoft.com/en-us/security/aa973814.aspx. This library is essentially the same library that we used to call IOSec (whose name is retiring so we can converge on a single name) and we’re excited about finally being able to provide you with tools like these to develop more secure applications!
Top 5 Reasons Why You Should Upgrade
Migrating to V1.5 will require a few steps on your part, but here are the top reasons why you should upgrade to this version:
Encoding Method
Version 1.0
Version 1.5
HtmlEncode
X
HtmlAttributeEncode
UrlEncode
JavaScriptEncode
VisualBasicScriptEncode
XmlEncode
XmlAttributeEncode
What’s Next?
Already people are asking this! In later versions we’ll look towards providing you with automatically encoding Web controls, intelligent filtering capabilities and much more. And of course, the ACE team will continue releasing other security tools (new versions of TAM, and others …) so keep visiting this blog for updates!
Thanks and enjoy this release!
Kevin Lam, CISSP | Senior Security Technologist | ACE Security Services Team Assessing Network Security Book - http://www.microsoft.com/MSPress/books/6788.asp Kevin Lam's Blog - http://blogs.msdn.com/kevinlam/default.aspx
Microsoft hat die Anti-Cross Site Scripting Library [1] nun in der Version 1.5 [2] veröffentlicht. Damit können Webanwendungen gegen Cross Site Scripting (XSS) abegehärtet werden. Mit der aktuellen Version sind auch Methoden für das absichern vo
微软的Anti-Cross Site Scripting Library旨在方便开发人员对HTML输出进行编码(encode)以避免跨站脚本攻击(XSS)。与其他的编码库不同,这个脚本库采用的是“Principle...
La fameuse librairie anti XSS est disponible depuis lundi sur le site de Microsoft. Il faut dire que cette nouvelle tombe
It all happens with input that us not properly validated from: http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMCh04.asp?frame=true#c04618429_006
Most folks know that cross-site scripting (XSS) bugs can be used to steal logon cookies, as this scenario
Lynn's slides - Jan 2008 Allup » SlideShare Original slides and session recordings - http://www.msdnevents.com/resources/2008-winter-resources.aspx
Lynn's slides - Jan 2008 Allup » SlideShare Original slides and session recordings - http://www.msdnevents