video thumbnail 12:35
The Age of Universal XSS

2022-09-23

[public] 9.5K views, 2.37K likes, dislikes audio only

channel thumbLiveOverflow

In August 1996, Internet Explorer joined the JavaScript security scene after they added JScript. During this era from around 1996-2000, tons of bugs were found what we would call today "Universal Cross-site Scripting". I find this word confusing, but looking back at the history, we can try to make sense of it.

Jabadoo Security Hole in Explorer 4.0: https://seclists.org/bugtraq/1997/Oct/85

Aleph One on Jabadoo: https://seclists.org/bugtraq/1997/Oct/87

Georgi Guninski "IE can read local files": https://seclists.org/bugtraq/1998/Sep/47

Georgi's Resume (HIRE HIM!): https://j.ludost.net/resumegg.pdf

"Cross-frame security policy": https://seclists.org/bugtraq/2000/Jan/93

Episode 01 - First JS Bug: /youtube/video/bSJm8-zJTzQ

Episode 02 - Three JS Security Researcher: /youtube/video/VtcA58555lY

Episode 03:

00:00 - Intro to the "Age of Universal XSS"

01:16 - JavaScript Security in Netscape 1996

01:52 - JScript Vulnerability in Internet Explorer

03:38 - Georgi Guninski: IE can read local files (1998)

05:12 - Who is Georgi Guninski?

06:36 - Georgi Guninski: IE 5 circumventing cross-frame security policy

09:41 - David Ross from Microsoft about Georgi

10:16 - "Cross-Frame" Browser Bugs

11:17 - Universal Cross-Site Scripting

12:15 - Outro

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Instagram: https://instagram.com/LiveOverflow/

→ Blog: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


The Same Origin Policy - Hacker History by LiveOverflow
/youtube/video/bSJm8-zJTzQ
The Three JavaScript Hacking Legends by LiveOverflow
/youtube/video/VtcA58555lY
Intro to the "Age of Universal XSS"
/youtube/video/gVblb-QhZa4?t=0
JavaScript Security in Netscape 1996
/youtube/video/gVblb-QhZa4?t=76
JScript Vulnerability in Internet Explorer
/youtube/video/gVblb-QhZa4?t=112
Georgi Guninski: IE can read local files (1998)
/youtube/video/gVblb-QhZa4?t=218
Who is Georgi Guninski?
/youtube/video/gVblb-QhZa4?t=312
Georgi Guninski: IE 5 circumventing cross-frame security policy
/youtube/video/gVblb-QhZa4?t=396
David Ross from Microsoft about Georgi
/youtube/video/gVblb-QhZa4?t=581
"Cross-Frame" Browser Bugs
/youtube/video/gVblb-QhZa4?t=616
Universal Cross-Site Scripting
/youtube/video/gVblb-QhZa4?t=677
Outro
/youtube/video/gVblb-QhZa4?t=735
I’m moving, no videos sorry 17,558 views
/youtube/video/9CS3q0uG1LI
Support liveoverflow.com
https://liveoverflow.com/support
LiveOverflow Web Hacking by LiveOverflow
/youtube/video/jmgsgjPn1vs