Tyler Reguly, lead security research engineer at nCircle, today published a white paper outlining a new category of attack called "meta-information XSS" (miXSS), which works differently than other forms of the popular attack method -- and could be difficult to detect.
"These Web-based services introduce a class of XSS that can't be captured by the current categories."
Reguly explains that there are three current types of XSS attacks: reflected, persistent, and DOM-based.
"Reflected XSS refers to an attack that occurs when user input is reflected back at the user," he writes. "This means that you provide the malicious data as user input, and the Web application simply echoes the data back to you.
The link for this article located at Dark Reading is no longer available.