<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>ASP.NET ValidateRequest does not mitigate XSS completely</title><link>http://blogs.msdn.com/b/esiu/archive/2007/10/19/asp-net-validaterequest-does-not-mitigate-xss-completely.aspx</link><description>As a security guy, I can safely say that there is no magic bullet to mitigate any security problems completely, and cross-site scripting(XSS) bugs are not exceptions. Since ASP.NET 1.1, ValidateRequest can be configured in web.config to check and reject</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>ASP.NET ValidateRequest and the HTML Attribute Based Cross Site Scripting </title><link>http://blogs.msdn.com/b/esiu/archive/2007/10/19/asp-net-validaterequest-does-not-mitigate-xss-completely.aspx#5790271</link><pubDate>Wed, 31 Oct 2007 06:45:18 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5790271</guid><dc:creator>KeepItLocked.net</dc:creator><description>&lt;p&gt;ASP.NET ValidateRequest is a security mechanism designed to prevent cross-site scripting attacks in ASP&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5790271" width="1" height="1"&gt;</description></item><item><title>Weekend Security Reading Round up Links - 10/20/07</title><link>http://blogs.msdn.com/b/esiu/archive/2007/10/19/asp-net-validaterequest-does-not-mitigate-xss-completely.aspx#5542285</link><pubDate>Sat, 20 Oct 2007 12:45:18 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5542285</guid><dc:creator>Noticias externas</dc:creator><description>&lt;p&gt;Inside the Matrix for Mobiles A pretty interesting concept: hack together a platform for connecting the&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5542285" width="1" height="1"&gt;</description></item><item><title>Weekend Security Reading Round up Links - 10/20/07</title><link>http://blogs.msdn.com/b/esiu/archive/2007/10/19/asp-net-validaterequest-does-not-mitigate-xss-completely.aspx#5541201</link><pubDate>Sat, 20 Oct 2007 11:40:17 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5541201</guid><dc:creator>%41%43%45%20%54%65%61%6d </dc:creator><description>&lt;p&gt;Inside the Matrix for Mobiles A pretty interesting concept: hack together a platform for connecting the&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5541201" width="1" height="1"&gt;</description></item><item><title>ASP.NET ValidateRequest does not mitigate XSS completely</title><link>http://blogs.msdn.com/b/esiu/archive/2007/10/19/asp-net-validaterequest-does-not-mitigate-xss-completely.aspx#5529858</link><pubDate>Sat, 20 Oct 2007 01:02:35 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5529858</guid><dc:creator>Noticias externas</dc:creator><description>&lt;p&gt;From Eugene Siu&amp;amp;#39;s blog: &lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/esiu/archive/2007/10/19/asp-net-validaterequest-does"&gt;http://blogs.msdn.com/esiu/archive/2007/10/19/asp-net-validaterequest-does&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5529858" width="1" height="1"&gt;</description></item><item><title>ASP.NET ValidateRequest does not mitigate XSS completely</title><link>http://blogs.msdn.com/b/esiu/archive/2007/10/19/asp-net-validaterequest-does-not-mitigate-xss-completely.aspx#5529207</link><pubDate>Sat, 20 Oct 2007 00:30:11 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5529207</guid><dc:creator>ACE Team - Security, Performance &amp; Privacy</dc:creator><description>&lt;p&gt;From Eugene Siu's blog: &lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/esiu/archive/2007/10/19/asp-net-validaterequest-does-not-mitigate-xss-completely.aspx"&gt;http://blogs.msdn.com/esiu/archive/2007/10/19/asp-net-validaterequest-does-not-mitigate-xss-completely.aspx&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5529207" width="1" height="1"&gt;</description></item></channel></rss>