alert(1) to win: https://escape.alf.nu/ neat XSS/escaping game
miniblog.
Related Posts
Facebook's warning against socially-engineered XSS is neat. It's a shame it's necessary though.
In the DOM, no one will hear you scream https://www.slideshare.net/x00mario/in-the-dom-no-one-will-hear-you-scream (argues that perfect server-side XSS protection is impossible!)
I'm favouring bower over CDNs these days. No risk of XSS.
