Together with the server-side stripslash() php function this call slips through the IE8 XSS filters because it strips the slashes server side and such evades IE8 detection when the HTTP request is being sent by IE8:
See: http://www.0x000000.com/?i=634
New Attacks Against Secure Enclaves
-
Encryption can protect data at rest and data in transit, but does nothing
for data in use. What we have are secure enclaves. I’ve written about this
befo...
15 hours ago


0 comments
Post a Comment