
Latest Web Vulnerability Trends & Best Practices - Patrick Vandenberg - ASW #245
Application Security Weekly (Audio)
00:00
Microsoft and Azure's Post-Message Exploitation
John Sutter: The interesting thing about it, at least, was in post-message. He says Microsoft forgot to actually create an allow list and follow a lot of the good practices that are stated even within the RFC or the spec for post- message. "I don't know if you have been digging into the nuances of modern-day cross-site scripting," he says.
Transcript
Play full episode