ha.ckers.org web application security lab - Archive ≫ NoScript Plugin Beta Attempts To Stop XSS

FireFoxNoScriptのベータ版(Noscript 1.1.4.6.070318)で外サイトのJavascriptを実行するタイプのXSSは止められるでしょうというお話。Internet Explorer版のNoScriptが欲しぃー!

Giorgio Maone, the author of the NoScript Firefox plugin has recently been posting to the boards about a new experimental version of the plugin that intends to protect against XSS. The concept of the tool change is to detect when one site is attempting to send you to another site with XSS within the query string. Obviously there are more ways to XSS sites than the query string, so this mostly relates to certain forms of reflected XSS.