Dom,

On Mon, Oct 29, 2012 at 5:01 PM, Dominique Righetto
<dominique.righe...@gmail.com> wrote:
> Hi,
>
> After reading links below:
> - https://blog.whitehatsec.com/content-security-policy/
> -
> https://developer.mozilla.org/en-US/docs/Security/CSP/Using_Content_Security_Policy
> - http://www.w3.org/TR/CSP/
>
> I 'm thinking that it can be a idea to create a GREP plugin type checking if
> a site include policy about is content loading (for example to mitigate XSS
> using a remote script,...).
>
> What do you think ?

+1 ! Good idea, please do it in the threading2 plugin format.

> If the idea is accepted then I will work on it :)
>
> Thanks in advance.
>
> --
> Cordialement, Best regards,
> Dominique Righetto
> dominique.righe...@gmail.com
> dominique.righe...@owasp.org
> Twitter: @righettod
> GPG: 0x323D19BA
> http://righettod.github.com
> "No trees were killed to send this message, but a large number of electrons
> were terribly inconvenienced."
>
> ------------------------------------------------------------------------------
> The Windows 8 Center - In partnership with Sourceforge
> Your idea - your app - 30 days.
> Get started!
> http://windows8center.sourceforge.net/
> what-html-developers-need-to-know-about-coding-windows-8-metro-style-apps/
> _______________________________________________
> W3af-develop mailing list
> W3af-develop@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/w3af-develop
>



-- 
Andrés Riancho
Project Leader at w3af - http://w3af.org/
Web Application Attack and Audit Framework
Twitter: @w3af
GPG: 0x93C344F3

------------------------------------------------------------------------------
The Windows 8 Center - In partnership with Sourceforge
Your idea - your app - 30 days.
Get started!
http://windows8center.sourceforge.net/
what-html-developers-need-to-know-about-coding-windows-8-metro-style-apps/
_______________________________________________
W3af-develop mailing list
W3af-develop@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/w3af-develop

Reply via email to