logo

Jesse's Blog

Helping Oneself to the PII of 800,000 Users and More

Why the server should never trust any data supplied by the client. Read more...

Architecting a Social Media Worm with XSS

Haven't you ever wanted to have more followers? Well now you can with a little help from cross-site scripting. Read more...

Having Some Fun With XSS

Sometimes a security issue isn't all that serious and you just want to have a bit of fun. Read more...

Customise Your Toy Shopping Experience with XSS

An example of why escaping HTML is important when rendering user-supplied data. Read more...

Deactivating Other People's Accounts on a Retail Website

Another reason to never trust that the user is who they say they are. Read more...