<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>XSS-Focused Attack Surface Reduction</title><link>http://blogs.msdn.com/dross/archive/2008/03/10/xss-focused-attack-surface-reduction.aspx</link><description>All web browsers expose what have been referred to as XSS “attack vectors” – various techniques that XSS attacks can leverage to achieve script execution. The best and most well regarded list of these behaviors is RSnake’s XSS Cheat Sheet . The existence</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>ha.ckers.org web application security lab  - Archive  &amp;raquo; IE8.0 US-ASCII and Other Stuff</title><link>http://blogs.msdn.com/dross/archive/2008/03/10/xss-focused-attack-surface-reduction.aspx#8366228</link><pubDate>Mon, 07 Apr 2008 22:15:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8366228</guid><dc:creator>ha.ckers.org web application security lab  - Archive  &amp;raquo; IE8.0 US-ASCII and Other Stuff</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://ha.ckers.org/blog/20080407/ie80-us-ascii-and-other-stuff/"&gt;http://ha.ckers.org/blog/20080407/ie80-us-ascii-and-other-stuff/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>IE8 Security Part IV: The XSS Filter</title><link>http://blogs.msdn.com/dross/archive/2008/03/10/xss-focused-attack-surface-reduction.aspx#8681607</link><pubDate>Wed, 02 Jul 2008 19:04:06 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8681607</guid><dc:creator>IEBlog</dc:creator><description>&lt;p&gt;Hi, I'm David Ross, Security Software Engineer on the SWI team. I’m proud to be doing this guest post&lt;/p&gt;
</description></item><item><title>IE8 XSS Filter design philosophy in-depth</title><link>http://blogs.msdn.com/dross/archive/2008/03/10/xss-focused-attack-surface-reduction.aspx#8687753</link><pubDate>Fri, 04 Jul 2008 10:25:34 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8687753</guid><dc:creator>random dross</dc:creator><description>&lt;p&gt;It's great to see some positive reaction to the potential of our XSS Filter. Now we just need to deliver!&lt;/p&gt;
</description></item><item><title>IE 8 XSS Filter Architecture / Implementation</title><link>http://blogs.msdn.com/dross/archive/2008/03/10/xss-focused-attack-surface-reduction.aspx#8884045</link><pubDate>Thu, 21 Aug 2008 11:34:41 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8884045</guid><dc:creator>Ruud de Jonge</dc:creator><description>&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/swi/archive/2008/08/19/ie-8-xss-filter-architecture-implementation.aspx"&gt;http://blogs.technet.com/swi/archive/2008/08/19/ie-8-xss-filter-architecture-implementation.aspx&lt;/a&gt; Recently&lt;/p&gt;
</description></item></channel></rss>