08 August 2007 | 5,544 views

XSS Warning – A Security Extension/Add-on for Firefox

Check For Vulnerabilities with Acunetix

XSS Warning is a extension/add-on for Firefox that filters malicious values to prevent Cross Site Scripting (XSS) attacks by malicious URLs (assuming you have Javascript enabled).

XSS Warning

XSS Warning 0.1.8 beta protect from:

  • URL attack
  • Redirect attack
  • Link code injection

Compatible with Firefox: 1.5 – 2.0.0

You can install and read more about XSS Warning here:

http://www.gianniamato.it/project/extension/xsswarning/



Recent in Countermeasures:
- HoneyDrive 3 Released – The Premier Honeypot Bundle Distro
- Codesake::Dawn – Static Code Analysis Security Scanner For Ruby
- Don’t Get Hacked – Have A Free Acunetix Security Scan

Related Posts:
- Malware Pushers Abuse Firefox Warning Page
- BlackSheep – Detect Users Of FireSheep On The Network
- Firefox Patches 8 Security Vulnerabilities with 2.0.0.1

Most Read in Countermeasures:
- AJAX: Is your application secure enough? - 119,075 views
- Password Hasher Firefox Extension - 116,967 views
- NDR or Backscatter Spam – How Non Delivery Reports Become a Nuisance - 57,545 views

Low-cost VPS Hosting

14 Responses to “XSS Warning – A Security Extension/Add-on for Firefox”

  1. moons 8 August 2007 at 7:32 am Permalink

    hm.. the webserver seems to be down

  2. Pedro 8 August 2007 at 1:32 pm Permalink

    The server is working fine now…

  3. Tonny DS 8 August 2007 at 4:03 pm Permalink

    NoScript add-on for Firefox is doing this too. It contains XSS blocking/warning and other security features.

    url: http://noscript.net

    disclaimer: I am not affiliated with noscript.net

  4. TheRealDonQuixote 8 August 2007 at 11:33 pm Permalink

    Hmm, I dunno about using a beta release for a Firefox. Remember all the trouble that came from FasterFox when it first hit the scene?

    Oh and Tony is right about noscript. It works pretty well. At least I hope!! ;)

    BTW- Is the extension always going to be in Italian?

  5. Sandeep Nain 9 August 2007 at 4:51 am Permalink

    No doubt really a good add on.. but still needs to be improved as there are several other ways of XSS attacks it doesn’t cover.

  6. Daniel 13 August 2007 at 1:03 pm Permalink

    i think that things like this encourage lax browsing habits.
    it puts people in a sense of false security, thinking that since they have this xss gaurd installed, they can fling their Mastercard all over the web.

  7. Sandeep Nain 16 August 2007 at 1:01 am Permalink

    Good one Daniel..

    I hope people will understand the difference between more secure and fully secure.. if they don’t then nobody can save them…

  8. Daniel 16 August 2007 at 1:43 am Permalink

    i think you should have to take a class or go to defcon or something before you are allowed to do e-commerce

    because there are so many stupid people out there.

  9. Sandeep Nain 16 August 2007 at 2:35 am Permalink

    well actually they dont need to do that… thats what hackers are for.. to teach them..if they get ripped off once…
    it will make them aware of these prevalent issues..
    also they will use their mastercard properly next time…

  10. Alfred Farrington 16 August 2007 at 6:27 pm Permalink

    Let’s be real how many people are “uninformed” of computer insecurities I am pretty sure the people who are getting hacked are still using IE instead of Firefox anyway. :)

  11. Alfred Farrington 16 August 2007 at 6:28 pm Permalink

    Not that Firefox makes you anymore secure but come on let’s be real here. People who read places like Darknet are the more informed ones.

  12. TheRealDonQuixote 16 August 2007 at 9:48 pm Permalink

    @Alfred
    Yeah, the peeps around here are knowledgeable about security, but in the average office workplace…

    I used to spend hours trying to convince my old office buddies to NOT surf with IE or at least turn off JS while they where dorking around on myspace.

    I doubt I am the only one here who has had to break the bad news to a friend that their MSN/Myspace/Gmail/Orkut/whatever account is gone and there is no way to get it back. Trying to explain basic practices for better security always yields the same response, “That’s too complicated, can’t you just…”

    Sometimes I think they all have to get hacked before they start realizing that a computer is a tool, not a toy.

  13. Sandeep Nain 17 August 2007 at 12:10 am Permalink

    TRDQ is absolutely right… I know so many people who think that computers is to help them and reduce their efforts. and now once they have internet and credit cads.. they can buy stuff sitting at home…

    and i FULLY AGREE with them… but these guys always forget that they have some responsibilities too.. and the very imp one is making themselves aware of the security threats… and also keeping their eyes open while making a transaction over internet