[Full-disclosure] Security Career Teleseminar/Podcast Series

2006-11-18 Thread Michael Murray
Hi, I know that this is slightly off-topic for FD, but I figured that this actually made sense - one of the skills that most security pros spend the least time on are those for developing a career in security rather than just bouncing from job to job. This is even more true in the vuln r

[Full-disclosure] Sage cross-context scripting -> LOCAL-CONTEXT SCRIPTING

2006-11-18 Thread pagvac
Correct me if I'm wrong but the following description from is wrong: "Attacker-supplied HTML and script code would execute in the context of the affected website" Code is NOT executed within the context of the affected site but rather within LOCAL