<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Some technical details on how XSSDetect does Dataflow Analysis </title><link>http://blogs.msdn.com/hackers/archive/2007/10/23/some-technical-details-on-how-xssdetect-does-dataflow-analysis.aspx</link><description>Hi, my name is Hassan Khan. I work for the ACE Engineering Team, which is a part of the ACE (Application Consulting &amp;amp; Engineering) Team . We develop tools and solutions to help secure Microsoft Line of Business applications, websites and also work</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Update: Some details on how XSSDetect does dataflow analysis</title><link>http://blogs.msdn.com/hackers/archive/2007/10/23/some-technical-details-on-how-xssdetect-does-dataflow-analysis.aspx#5642926</link><pubDate>Wed, 24 Oct 2007 10:09:55 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5642926</guid><dc:creator>ACE Team - Security, Performance &amp; Privacy</dc:creator><description>&lt;p&gt;Just a brief update, Hassan Khan one of the lead developers of XSSDetect and part of our ACE Engineering&lt;/p&gt;
</description></item><item><title>Some details on how XSSDetect does dataflow analysis</title><link>http://blogs.msdn.com/hackers/archive/2007/10/23/some-technical-details-on-how-xssdetect-does-dataflow-analysis.aspx#5646343</link><pubDate>Wed, 24 Oct 2007 13:06:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5646343</guid><dc:creator>Ravikanth's Blog </dc:creator><description>&lt;p&gt;ACE Engineering team has posted up some technical details on how XSSDetect uses data flow analysis to&lt;/p&gt;
</description></item><item><title>re: Some technical details on how XSSDetect does Dataflow Analysis </title><link>http://blogs.msdn.com/hackers/archive/2007/10/23/some-technical-details-on-how-xssdetect-does-dataflow-analysis.aspx#5650182</link><pubDate>Wed, 24 Oct 2007 16:44:39 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5650182</guid><dc:creator>orysegal</dc:creator><description>&lt;P&gt;Quote: "Most tools in the market, if not all, are not very good at it. Static analysis tools on the other hand scan the application source code or binaries to detect programming errors. Consequently, they offer 100% coverage and are able to identify many more vulnerabilities than penetration testing tools. XSSDetect is a static analysis tool. "&lt;/P&gt;
&lt;P&gt;Harsh words, and without a lot of basis on real facts if I may add. Ask around actual customers of source code analysis tools, and they will bitch and complain about the amount of false positives and noise that these tools produce.&lt;/P&gt;
&lt;P&gt;Preferring whitebox over blackbox is ridiculous. One technique on its own will never be able to provide 100% security coverage.&lt;/P&gt;</description></item><item><title>[ASP.NET] XSS Detect (beta)</title><link>http://blogs.msdn.com/hackers/archive/2007/10/23/some-technical-details-on-how-xssdetect-does-dataflow-analysis.aspx#5662596</link><pubDate>Thu, 25 Oct 2007 10:44:05 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5662596</guid><dc:creator>biac の それさえもおそらくは幸せな日々@nifty</dc:creator><description>&lt;p&gt;MS ダウンロードセンターより。 XSS Detect Beta Code Analysis Tool Version: 1.0Date Published:&lt;/p&gt;
</description></item><item><title>XSSDetect: Cross Site Scripting detection plug-in for Visual Studio 2005</title><link>http://blogs.msdn.com/hackers/archive/2007/10/23/some-technical-details-on-how-xssdetect-does-dataflow-analysis.aspx#5670783</link><pubDate>Thu, 25 Oct 2007 18:28:09 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5670783</guid><dc:creator>Blake Niemyjski</dc:creator><description>&lt;p&gt;The &amp;amp;quot;Ace&amp;amp;quot; team inside of Microsoft has kindly released a plug-in for Visual Studio called XSSDetect&lt;/p&gt;
</description></item><item><title>XSSDetect : première beta publique de l'outil d'analyse statique disponible</title><link>http://blogs.msdn.com/hackers/archive/2007/10/23/some-technical-details-on-how-xssdetect-does-dataflow-analysis.aspx#5737678</link><pubDate>Sun, 28 Oct 2007 15:26:03 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5737678</guid><dc:creator>CoqBlog</dc:creator><description>&lt;p&gt;XSSDetect est un addin pour Visual Studio destin&amp;#233; &amp;#224; aider l'utilisateur &amp;#224; &amp;#233;liminer les probl&amp;#232;mes d' XSS&lt;/p&gt;
</description></item><item><title>Link to public beta of XSSDetect cross-site scripting code analysis plug-in for Visual Studio 2005</title><link>http://blogs.msdn.com/hackers/archive/2007/10/23/some-technical-details-on-how-xssdetect-does-dataflow-analysis.aspx#5752558</link><pubDate>Mon, 29 Oct 2007 04:57:23 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5752558</guid><dc:creator>Aaron Stebner's WebLog</dc:creator><description>&lt;p&gt;I ran across a few interesting posts on the Application Consulting and Engineering (ACE) team's blog&lt;/p&gt;
</description></item></channel></rss>