XSS Warning – A Security Extension/Add-on for Firefox

Outsmart Malicious Hackers


XSS Warning is a extension/add-on for Firefox that filters malicious values to prevent Cross Site Scripting (XSS) attacks by malicious URLs (assuming you have Javascript enabled).

XSS Warning

XSS Warning 0.1.8 beta protect from:

  • URL attack
  • Redirect attack
  • Link code injection

Compatible with Firefox: 1.5 – 2.0.0

You can install and read more about XSS Warning here:

http://www.gianniamato.it/project/extension/xsswarning/

Posted in: Countermeasures, Security Software

,


Latest Posts:


snallygaster - Scan For Secret Files On HTTP Servers snallygaster – Scan For Secret Files On HTTP Servers
snallygaster is a Python-based tool that can help you to scan for secret files on HTTP servers, files that are accessible that shouldn't be public and can pose a s
Portspoof - Spoof All Ports Open & Emulate Valid Services Portspoof – Spoof All Ports Open & Emulate Valid Services
The primary goal of the Portspoof program is to enhance your system security through a set of new camouflage techniques which spoof all ports open and also emulate valid services on every port.
Cambridge Analytica Facebook Data Scandal Cambridge Analytica Facebook Data Scandal
One of the biggest stories of the year so far has been the scandal surrounding Cambridge Analytica that came out after a Channel 4 expose that demonstrated the depths they are willing to go to profile voters, manipulate elections and much more.
GetAltName - Discover Sub-Domains From SSL Certificates GetAltName – Discover Sub-Domains From SSL Certificates
GetAltName it's a little script to discover sub-domains that can extract Subject Alt Names for SSL Certificates directly from HTTPS websites which can provide you with DNS names or virtual servers.
Memcrashed - Memcached DDoS Exploit Tool Memcrashed – Memcached DDoS Exploit Tool
Memcrashed is a Memcached DDoS exploit tool written in Python that allows you to send forged UDP packets to a list of Memcached servers obtained from Shodan.
QualysGuard - Vulnerability Management Tool QualysGuard – Vulnerability Management Tool
QualysGuard is a web-based vulnerability management tool provided by Qualys, Inc, which was the first company to deliver vulnerability management services as a SaaS-based web-service.


13 Responses to XSS Warning – A Security Extension/Add-on for Firefox

  1. moons August 8, 2007 at 7:32 am #

    hm.. the webserver seems to be down

  2. Pedro August 8, 2007 at 1:32 pm #

    The server is working fine now…

  3. Tonny DS August 8, 2007 at 4:03 pm #

    NoScript add-on for Firefox is doing this too. It contains XSS blocking/warning and other security features.

    url: http://noscript.net

    disclaimer: I am not affiliated with noscript.net

  4. TheRealDonQuixote August 8, 2007 at 11:33 pm #

    Hmm, I dunno about using a beta release for a Firefox. Remember all the trouble that came from FasterFox when it first hit the scene?

    Oh and Tony is right about noscript. It works pretty well. At least I hope!! ;)

    BTW- Is the extension always going to be in Italian?

  5. Sandeep Nain August 9, 2007 at 4:51 am #

    No doubt really a good add on.. but still needs to be improved as there are several other ways of XSS attacks it doesn’t cover.

  6. Daniel August 13, 2007 at 1:03 pm #

    i think that things like this encourage lax browsing habits.
    it puts people in a sense of false security, thinking that since they have this xss gaurd installed, they can fling their Mastercard all over the web.

  7. Sandeep Nain August 16, 2007 at 1:01 am #

    Good one Daniel..

    I hope people will understand the difference between more secure and fully secure.. if they don’t then nobody can save them…

  8. Daniel August 16, 2007 at 1:43 am #

    i think you should have to take a class or go to defcon or something before you are allowed to do e-commerce

    because there are so many stupid people out there.

  9. Sandeep Nain August 16, 2007 at 2:35 am #

    well actually they dont need to do that… thats what hackers are for.. to teach them..if they get ripped off once…
    it will make them aware of these prevalent issues..
    also they will use their mastercard properly next time…

  10. Alfred Farrington August 16, 2007 at 6:27 pm #

    Let’s be real how many people are “uninformed” of computer insecurities I am pretty sure the people who are getting hacked are still using IE instead of Firefox anyway. :)

  11. Alfred Farrington August 16, 2007 at 6:28 pm #

    Not that Firefox makes you anymore secure but come on let’s be real here. People who read places like Darknet are the more informed ones.

  12. TheRealDonQuixote August 16, 2007 at 9:48 pm #

    @Alfred
    Yeah, the peeps around here are knowledgeable about security, but in the average office workplace…

    I used to spend hours trying to convince my old office buddies to NOT surf with IE or at least turn off JS while they where dorking around on myspace.

    I doubt I am the only one here who has had to break the bad news to a friend that their MSN/Myspace/Gmail/Orkut/whatever account is gone and there is no way to get it back. Trying to explain basic practices for better security always yields the same response, “That’s too complicated, can’t you just…”

    Sometimes I think they all have to get hacked before they start realizing that a computer is a tool, not a toy.

  13. Sandeep Nain August 17, 2007 at 12:10 am #

    TRDQ is absolutely right… I know so many people who think that computers is to help them and reduce their efforts. and now once they have internet and credit cads.. they can buy stuff sitting at home…

    and i FULLY AGREE with them… but these guys always forget that they have some responsibilities too.. and the very imp one is making themselves aware of the security threats… and also keeping their eyes open while making a transaction over internet