Skip to Content
ASP.NET Core Security
book

ASP.NET Core Security

by Christian Wenz
July 2022
Beginner to intermediate
368 pages
9h 48m
English
Manning Publications
Content preview from ASP.NET Core Security

2 Cross-site scripting (XSS)

This chapter covers

  • Understanding how cross-site scripting (XSS) works
  • Learning about different types of XSS
  • Preventing XSS by escaping output
  • Using Content Security Policy (CSP) against XSS
  • Judging other browser features against XSS

In 2014, the BBC reported (https://www.bbc.com/news/technology-29241563) that clicking on certain links on eBay would redirect users to a phishing site: it looked similar to eBay, but, of course, wasn’t legitimate. The security researcher who found the vulnerability supposedly contacted the firm to no avail. An official inquiry by the BBC then sped things up, and the issue was resolved.

About 10 years earlier, a security researcher managed to pull a similar stunt, redirecting eBay users ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Pro ASP.NET Core Identity: Under the Hood with Authentication and Authorization in ASP.NET Core 5 and 6 Applications

Pro ASP.NET Core Identity: Under the Hood with Authentication and Authorization in ASP.NET Core 5 and 6 Applications

Adam Freeman

Publisher Resources

ISBN: 9781633439986Publisher SupportOtherPublisher WebsiteSupplemental ContentErrata PagePurchase Link